https://news.aibase.com/news/27628
Cross-border Dark Horse Tops Two Charts! Shengshu
Technology Launches MotuBrain, Defining a New Standard for Embodied
Intelligence Brain
Published in Latest AI News
Time :Apr 30, 2026
Read :5minute
The identity of the "mysterious model" that has
been lingering in the field of embodied intelligence for three weeks has
finally been revealed. Previously, a model named MotuBrain quietly
topped two major international benchmarks for physical world understanding and
action execution, sparking widespread speculation in the industry.
Recently, Shengshu Technology, which has gained fame through the video
large model Vidu, officially announced that this model is its latest commercial
achievement in the field of embodied intelligence.
This "cross-border" effort is no mere experiment.
MotuBrain set new records in WorldArena (assessing physical world
understanding) and RoboTwin 2.0 (assessing action execution). Especially in
complex environments with simulated random disturbances, it was the only model
to achieve an average score above 95, demonstrating strong generalization
capabilities.
"See and Act": Breaking the Boundaries Between
Perception and Action
Differing from traditional "imagine first, then
act" models, MotuBrain adopts an innovative "World Action
Model" approach. This "see and act" design allows robots to
simulate while making decisions, ensuring that prediction and execution errors
do not amplify each other, greatly improving response speed.
In practical demonstrations, the robot equipped with this
system showed a high level of intelligence. In a hot pot scenario, the robot
could visually determine if the spoon was empty and decide autonomously whether
to retrieve it again, rather than rigidly repeating preset actions. This
"reading the room" ability marks the transition of robots from simple
mechanical execution to true intelligent decision-making.
One Brain, Multiple Forms: Smooth Integration of
Long-Term Tasks
The core advantage of MotuBrain lies in its strong
versatility. It not only supports "one brain, multiple forms,"
adapting to different degrees of freedom and sensor-equipped robot bodies, but
also possesses long-term task processing capabilities. In demonstrations such
as flower arranging, mixing cocktails, and tidying up the sofa, the robot can
complete more than 10 atomic actions continuously, with a smooth process
requiring no human intervention.
Data shows that as the variety of tasks increases, the
learning success rate of MotuBrain tends to rise. This indicates that
the model has mastered the universal underlying laws of the physical world,
rather than memorizing action templates. The more diverse the tasks, the better
its performance.
Establishing a Presence in the Physical World, Pursuing
Dual Tracks of Digital and Physical Realms
The strength demonstrated by Shengshu
Technology stems from its deep technical foundation. Through the
world-first U-ViT architecture, the company achieved unification between
digital world generation (VGM) and physical world execution (WAM). On one
hand, Vidu generates virtual worlds, while on the
other, MotuBrain drives physical interactions. This dual-track
strategy gives it a significant advantage in data acquisition costs and model
iteration speed.
Currently, Shengshu Technology
has reached strategic partnerships with several companies, including WuJie
Dynamics and XingChen Intelligence. As the focus of competition in embodied
intelligence shifts, model developers with a general-purpose "brain"
are becoming key forces in reshaping the industry landscape.
Funksec is a newly identified extortion group that has
claimed 11 victims across various sectors, including media, IT, and education,
operating a Tor-based DLS to centralize its ransomware activities. The group
advertises a free DDoS tool and may develop its own ransomware binary,
indicating significant technical capability. The DLS was likely created in late
November to early December 2024, with the first advertisement titled “Funksec
Ransomware” posted on 3 December 2024. Currently, there is limited publicly
available information on Funksec's TTPs, and it is not known to be associated
with any other threat groups.
FunkSec is an AI-assisted
ransomware-as-a-service (RaaS) group that emerged in late 2024 and
rapidly gained notoriety for claiming over 120 victims across
industries including government, healthcare, and finance. The group
is characterized by its double extortion tactics, combining data
encryption with theft, and its use of hacktivist rhetoric alongside
financially motivated attacks.
Key operational details include:
- Malware: The
group uses FunkLocker, a Rust-based ransomware
that encrypts files using ChaCha20 and appends the .funksec extension. - AI
Integration: FunkSec leverages Generative AI to
assist in malware development, phishing template creation, and code
refinement, lowering the barrier for less experienced actors. - Access
Methods: Initial access is typically gained through phishing
emails, credential stuffing, and exploiting unpatched
vulnerabilities in exposed systems like RDP and VPNs. - Extortion
Strategy: The group demands unusually low ransoms (sometimes
as low as $10,000) and additionally sells stolen data to third
parties at discounted prices on dark web markets. - Geographic
Base: Technical analysis suggests the primary developer is likely
based in Algeria, with the group targeting organizations in
the U.S., India, Spain, and Mongolia.
What are the specific indicators of FunkLocker malware?
FunkLocker (FunkSec) — Specific Indicators of Compromise
File Hashes (SHA-256)
Hash | Description |
c233aec7917cf34294c19dd60ff79a6e0fac5ed6f0cb57af98013c08201a7a1c | FunkLocker ransomware executable |
e29d95bfb815be80075f0f8bef4fa690abcc461e31a7b3b73106bfcd5cd79033 | Ransom note file |
66dbf939c00b09d8d22c692864b68c4a602e7a59c4b925b2e2bef57b1ad047bd | Additional sample |
dcf536edd67a98868759f4e72bcbd1f4404c70048a2a3257e77d8af06cb036ac | Additional sample |
b1ef7b267d887e34bf0242a94b38e7dc9fd5e6f8b2c5c440ce4ec98cc74642fb | Additional sample |
5226ea8e0f516565ba825a1bbed10020982c16414750237068b602c5b4ac6abd | Additional sample |
e622f3b743c7fc0a011b07a2e656aa2b5e50a4876721bcf1f405d582ca4cda22 | Additional sample |
20ed21bfdb7aa970b12e7368eba8e26a711752f1cc5416b6fd6629d0e2a44e5d | Additional sample |
dd15ce869aa79884753e3baad19b0437075202be86268b84f3ec2303e1ecd966 | Additional sample |
7e223a685d5324491bcacf3127869f9f3ec5d5100c5e7cb5af45a227e6ab4603 | Additional sample |
File & Artifact Indicators
- Encrypted
file extension: .funksec - Ransom
note names: README-[random_string].md, readme.txt (e.g., README-ZasRvdSR44.md) - Source
code artifact: *ransomware.rs* (Rust source) - Hardcoded
strings in binary: RansomwarePassword123, "device has
been successfully infiltrated by funksec ransomware!"
Network / Infrastructure IOCs
Type | Indicator |
Scorpion (leak site) | hxxps://miniapps[.]ai/funksec |
Malware hosting | hxxps://gofile[.]io/d/8FOSeP |
Darknet leak site | hxxp://funknqn44slwmgwgnewne6bintbooauwkaupik4yrlgtycew3ergraid[.]onion/ |
Darknet leak site | hxxp://funkiydk7c6j3vvck5zk2giml2u746fa5irwalw2kjem6tvofji7rwid[.]onion/ |
BTC wallet | Reused across victims (~$3,000 total transactions) |
Behavioral / Command-Line IOCs
These are the specific commands FunkLocker executes
via living-off-the-land tools:
Tool | Command | Purpose |
PowerShell | Set-MpPreference -DisableRealtimeMonitoring | Disable Windows Defender |
PowerShell | Set-ExecutionPolicy Bypass -Scope Process | Allow unrestricted script execution |
wevtutil.exe | wevtutil sl Security /e:false | Disable Security event logging |
wevtutil.exe | wevtutil sl Application /e:false | Disable Application event logging |
vssadmin.exe | vssadmin delete shadows /all /quiet | Delete Volume Shadow Copies |
taskkill.exe | taskkill /F /IM | Force-terminate Office, browsers, etc. |
sc.exe | sc stop | Stop Windows services |
net.exe | Network share/session discovery | Reconnaissance |
MITRE ATT&CK Mapping
Technique ID | Technique |
T1036.005 | Masquerading: Match Legitimate Resource Name or Location |
T1486 | Data Encrypted for Impact |
T1490 | Inhibit System Recovery |
T1489 | Service Stop |
T1059.001 | Command and Scripting Interpreter: PowerShell |
T1135 | Network Share Discovery |
T1562.001 | Defense Evasion: Disable or Modify Tools |
T1569.002 | Service Execution: Service Commands |
YARA Rule (for endpoint scanning)
rule funklocker_ransomware {
meta:
description =
"Detects Funklocker ransomware or similar variants"
author =
"Oluwaseyi Soneye"
reference =
"Strings output analysis"
date =
"2025-11-10"
strings:
$x1 =
"Set-MpPreference -DisableRealtimeMonitoring" nocase
$x2 =
"wevtutil sl Security /e:false" nocase
$x3 =
"wevtutil sl Application /e:false" nocase
$x4 =
"Set-ExecutionPolicy Bypass -Scope Process" nocase
$x5 =
"Set-MpPreference -DisableRealtimeMonitoring $truewevtutil sl Security
/e:falsewevtutil sl Application /e:falseSet-ExecutionPolicy" nocase
$x6 =
"vssadmindelete shadows/all/quiet" nocase
$x7 =
"taskkill/F/IM" nocase
$x8 =
"RansomwarePassword123" nocase
$x9 =
"device has been successfully infiltrated by funksec ransomware!"
nocase
$x10 =
"funksec" nocase
condition:
uint16(0) ==
0x5a4d and
(
(5 of ($x1,
$x2, $x3, $x4, $x5, $x6, $x7)) or
(2 of ($x8,
$x9, $x10))
)
}
Note: Avast Labs released a public
decryptor for FunkLocker victims due to the group's weak operational
security (reused BTC wallets and hardcoded keys). The No
More Ransom portal also provides recovery guidance.
What are the symptoms of infection?
Symptoms of a FunkLocker Infection
Immediate / User-Visible Symptoms
- Files
encrypted with the .funksec extension
(e.g., report.pdf → report.pdf.funksec) - Desktop
wallpaper turns black (Shell Experience Host service is
terminated) - Ransom
note (README-[random_string].md) dropped on the desktop — though
due to system instability, victims often cannot see it until after
a reboot - Applications
crash or stop working — the malware force-terminates ~50 common
processes (Office, browsers, taskmgr, etc.) - System
becomes largely unusable — services are stopped, leaving the OS
in a broken state
System-Level Symptoms (observable in logs / monitoring)
Symptom | What's happening |
Windows Defender real-time protection disabled | Set-MpPreference -DisableRealtimeMonitoring |
Security & Application event logs disabled | wevtutil sl Security /e:false |
Volume Shadow Copies deleted | vssadmin delete shadows /all /quiet |
Multiple processes/services force-killed | taskkill /F /IM, sc stop |
PowerShell execution policy set to Bypass | Set-ExecutionPolicy Bypass -Scope Process |
Sudden network slowdowns | Encryption of files across network shares |
Unusual outbound connections | Data exfiltration to attacker infrastructure |
Post-Encryption / Extortion Phase
- Within 24–48
hours, a leak site posting appears on the dark web
(.onion), threatening to publish exfiltrated data - Ransom
note directs the victim to a Tor site with a unique victim ID and
a Bitcoin wallet address - Payment
deadline of 3–5 days is typically stated - The
note warns against contacting authorities, using antivirus, or modifying
the system
Important Context
Threat actors typically infiltrate the system 2–4
weeks before encryption occurs. By the time visible
symptoms appear, data has already been exfiltrated. The encryption
event itself is fast (local-only, no C2 callback), but the overall attack
timeline spans weeks.
Antivirus Detections (at execution time)
- Microsoft: Trojan:Win32/Wacatac.B!ml
- Kaspersky: Trojan.Win32.DelShad.myd
- ESET: A
Variant Of Generik.GZBNBIS
If any of these symptoms are observed, the recommended
immediate actions are: disconnect from the network, do not reboot
or restore from backups (to preserve forensic evidence), and engage an incident
response team.
What specific malware families are similar to FunkLocker?
Malware Families Similar to FunkLocker
Similarity depends on which axis you're comparing. Here are
the closest matches by shared characteristic:
Rust-Based Ransomware (same language)
Family | Key Similarity | Notable Difference |
BlackCat (ALPHV) | Rust, ChaCha20 encryption, RaaS, double/triple extortion, | Far more mature, API-driven negotiation portal, triple |
Cicada3301 | Rust, ChaCha20, cross-platform (Win/Linux/ESXi/NAS/PowerPC), | Emerged mid-2024, more polished |
Hive | Rust (ported from Go), double extortion | Windows-only, older, less active |
Nokoyawa | Rust (v2.0, 2022), double extortion, ECC encryption | Originally C, ported to Rust; Windows-only |
Qilin (Agenda) | Rust (ported from Go), double extortion, RaaS, most active | More established, broader victimology |
3AM (ThreeAM) | Rust, VSS deletion, service stopping, double extortion, | Simpler, 64-bit only, less sophisticated |
Luna | Rust, cross-platform (Win/Linux/ESXi), Curve25519 + AES | Russian-speaking affiliates, simpler structure |
01flip | Rust, multi-platform (Win/Linux), double extortion | Newer (2025), possible LockBit overlap |
Embargo | Rust, suspected rewrite of ALPHV code | Less active |
RALord | Rust ransomware (reported 2025) | Limited public detail |
AI-Assisted / AI-Generated Code (same development
pattern)
Family | Similarity |
PromptLocker | AI-generated ransomware (educational demo, not malicious) |
Koske | AI-generated Linux-targeting malware |
CyberLock | AI-themed lures for distribution |
Lucky_Gh0$t | AI-themed lures |
Numero | AI-themed lures |
Local-Only Encryption (no C2 callback during encryption)
Family | Similarity |
Mamona | Entirely local encryption, no network callback — same |
Shared TTPs (defense evasion + disruption)
Families that share FunkLocker's specific "disable AV →
disable logging → delete VSS → kill processes → encrypt" kill chain:
- LockBit
3.0 — same VSS deletion, service stopping, but far more sophisticated
(AES-256 + RSA-2048, self-propagating) - Phobos —
similar TTPs, uses Smokeloader/Cobalt Strike/Mimikatz, targets public
sector - Black
Basta — Conti code lineage, double extortion, service disruption - RansomHub —
dominant post-LockBit RaaS, double extortion
Closest Overall Analogue
BlackCat/ALPHV is the most frequently cited
comparison point: both are Rust, both use ChaCha20, both operate as RaaS with
double/triple extortion, and both target cross-platform
environments. The key distinction is that BlackCat is a mature,
well-funded operation while FunkLocker is a low-skill, AI-assisted operation
with inconsistent code quality and weaker operational security (reused wallets,
hardcoded keys).
Cicada3301 is technically the closest match —
Rust + ChaCha20 + cross-platform + similar configuration patterns — but it
emerged independently and is more polished.
What specific AI tools generated FunkLocker's code?
Specific AI Tools Used to Generate FunkLocker's Code
The short answer: no single specific LLM model has
been definitively identified as the code
generator. Researchers consistently refer to "LLM agents"
generically. However, two specific tools/platforms have been confirmed:
Confirmed Tools
Tool | Role |
Miniapps | Platform used to build a custom AI chatbot ("Scorpion") |
ChatGPT | Used to generate summaries of the |
What Researchers Could NOT Confirm
The actual code-generating LLM (the one that
produced the Rust source in ransomware.rs) was never pinned to a specific
model (e.g., GPT-4, Claude, Llama, etc.). The evidence points to a generic
"LLM agent" workflow:
- "Ask
AI → Get snippet → Paste snippet" development cycle (ANY.RUN) - Perfect
English code comments vs. very basic English in the group's other
communications (Check Point, Kaspersky, CSO Online) - Generic
placeholder comments like "placeholder for actual check" (Kaspersky) - Technical
inconsistencies — commands for different operating systems mixed in the
same file (Kaspersky, Red Hot Cyber) - Declared
but unused functions and modules (Kaspersky) - Redundant
call functions and repeating control flow (Check Point) - Seven
distinct builds compiled in six days — a pace consistent with prompt-based
iteration rather than manual development (Palo Alto Unit 42, August
2026)
Summary
The Miniapps platform is
the only specifically named tool tied to code generation. The
underlying LLM model behind Miniapps' output was not disclosed or fingerprinted
by any researcher. ChatGPT was used for
documentation/summarization, not for generating the Rust source itself. The
development pattern is best described as "vibecoding" —
iterative prompting with an LLM to produce and patch code fragments without
deep understanding of the output.
What is the Miniapps platform?
Miniapps.ai
Miniapps.ai is
a no-code AI app builder and marketplace, launched in May
2023 and based in San Francisco, CA (~10
employees). It lets anyone create, publish, and share small
AI-powered "mini apps" — essentially prompt templates wired
to user inputs and backed by a choice of LLMs.
How It Works
- Pick a model —
GPT-4o, Claude, Gemini, Grok, DeepSeek, or image models (Flux, etc.) - Define prompt logic —
write system instructions and input fields via a visual editor (no coding) - Publish instantly —
the mini-app gets a shareable URL; others can use or clone it
What It Hosts
The platform functions as both
a builder and a discovery catalogue (think
"app store for AI micro-tools"). Community-created apps
span:
- Chatbots & roleplay
characters - SEO / marketing / social
media generators - Image generation & face
swap - Language tutors, AI
therapists - Games, simulators, coding
assistants - Productivity utilities
(calculators, form tools)
Pricing
Freemium — free tier
for basic usage; premium credits unlock higher usage limits or access to more
advanced models.
Relevance to FunkSec
The FunkSec group used Miniapps.ai
to build "Scorpion", a custom AI chatbot hosted
at miniapps[.]ai/funksec. Researchers noted the platform was chosen
because it lacks the content-safety guardrails of mainstream
tools like ChatGPT, making it easier to build an uncensored assistant for code
generation and operational support without triggering refusals. This mirrors a
broader pattern of threat actors exploiting permissive no-code AI platforms to
lower the barrier to building malware tooling.
FunkSec Domain &
Infrastructure Indicators
A key point: FunkLocker
has no traditional C2 domains — the encryption is entirely local with
no callback. The group's web infrastructure is limited to leak
sites, a chat server, and a few hosting/delivery URLs, mostly on Tor.
Tor (.onion) Domains
Domain | Purpose | Status (as of recent scan) |
funkxxkovrk7ctnggbjnthdajav4ggex53k6m2x3esjwlxrkb3qiztid[.]onion | Data Leak Site (DLS) | Up (~40% uptime 30d) |
funknqn44slwmgwgnewne6bintbooauwkaupik4yrlgtycew3ergraid[.]onion | DLS (previous) | Down (~27% uptime) |
funkiydk7c6j3vvck5zk2giml2u746fa5irwalw2kjem6tvofji7rwid[.]onion | DLS (previous) | Down (~23% uptime) |
funk4ph7igelwpgadmus4n4moyhh22cib723hllneen7g2qkklml4sqd[.]onion | FunkForum (affiliate | Down |
funkhnsbaxojjjju65bhc7xuidjwvmwhdmgarvhbhs3szqkpzkmvnvid[.]onion | FunkBID (data | Down |
funk45xqgrkrtej4743evcgv65oi3w4shwvjx3cvrdtqwul7gzkxuxqd[.]onion | Chat/Negotiation server | Down |
funksec53xh7j5t6ysgwnaidj5vkh3aqajanplix533kwxdz3qrwugid[.]onion | DLS v3.0 | Down |
funksecsekgasgjqlzzkmcnutrrrafavpszijoilbd6z3dkbzvqu43id[.]onion | DLS (previous) | Down |
funkyiazgfsrxrib6rnxbhkgfqi7isisfbqnwk2ycf7tpgfhtevlamad[.]onion | DLS (previous) | Down |
pke2vht5jdeninupk7i2thcfvxegsue6oraswpka35breuj7xxz2erid[.]onion | DLS (previous) | Down |
ykqjcrptcai76ru5u7jhvspkeizfsvpgovton4jmreawj4zdwe4qnlid[.]onion | DLS (previous) | Down |
7ixfdvqb4eaju5lzj4gg76kwlrxg4ugqpuog5oqkkmgfyn33h527oyyd[.]onion | DLS (previous) | Down |
Clearnet Domains & URLs
Domain / URL | Purpose | Notes |
funksec[.]top | Clearnet leak site mirror | Down; was hosted on "Anon |
miniapps[.]ai/funksec | Scorpion AI chatbot | The Miniapps-hosted AI assistant |
gofile[.]io/d/8FOSeP | Malware binary hosting | Distribution of FunkLocker |
176.113.115[.]19 | Naked IP dropper | Delivered ScreenUpdateSync.exe (dropper) |
Other Referenced Infrastructure
- ip-api[.]com —
referenced in some samples (likely for geolocation/lookup, not
attacker-controlled) - i[.]imgur[.]com —
image hosting referenced in some samples (abuse of legitimate service)
What Does NOT Exist
- No dedicated C2 domains —
the malware never phones home during encryption - No DGA (Domain Generation
Algorithm) — despite some low-quality AI-generated articles
claiming an "AI-assisted DGA," no researcher has identified
one. The group's infrastructure is simple and static - No fast-flux or rotating
domain patterns — the .onion addresses are fixed per instance,
just rotated when taken down
Summary
FunkSec's web footprint is minimal
and mostly dead. The group relies on a small set of rotating .onion leak
sites (currently only one is up), a single clearnet domain (funksec.top, down),
and the Miniapps.ai chatbot. The absence of C2 infrastructure is a defining
characteristic — it's both a limitation (no remote control, no key retrieval
channel) and a byproduct of the AI-generated, low-skill development approach.
Domain | Purpose | Status |
funksec.top | Clearnet mirror of the Data Leak | Down (hosted on |
Everything else in their clearnet
footprint is a subpath on a third-party platform, not a domain they
own:
URL | Platform | Purpose |
miniapps.ai/funksec | Miniapps.ai | Scorpion AI chatbot |
gofile.io/d/8FOSeP | GoFile | Malware binary distribution |
fastupload.com/... | FastUpload | Leak data downloads |
And one naked IP used
as a dropper:
IP | Purpose |
176.113.115.19 | Delivered ScreenUpdateSync.exe (dropper) |
