FunkSec is a financially motivated ransomware and data-extortion group that emerged in late 2024 and rapidly became one of the most prolific leak-site actors for a period in 2025. The group is notable for extensive use of generative AI and large language models to accelerate operations, including development or refinement of ransomware code, creation of phishing templates, generation of new malware variants, and operation of victim negotiation chatbots. Reporting consistently characterizes the group as having comparatively limited in-house technical sophistication while compensating through AI-assisted tooling. FunkSec has operated as a ransomware-as-a-service actor and has also offered supporting offensive tooling, including homegrown distributed-denial-of-service capabilities. Its activity is associated with leak-site operations, data auction infrastructure, and forum presence, including FunkBID and FunkForum. The group has been linked to double-extortion behavior through victim disclosures on leak infrastructure, and it has been cited in broader reporting on ransomware actors that combine encryption, data theft, and pressure tactics. Some reporting also places FunkSec among scam- or fabulist-adjacent actors because portions of its victim claims overlapped with or appeared copied from other ransomware operations, although confirmed victims were later reported. Victimology indicates a strong concentration in the United States, India, and Brazil. Frequently cited target sectors include technology, government, and education, with universities specifically identified among organizations affected by persistent FunkSec ransomware activity. Government agencies accounted for a notable share of the group’s claimed activity, though confirmation rates for those claims were lower than for some peer groups. Technically, FunkSec has been associated with Rust-based ransomware and AI-assisted malware development. The group has been discussed as an example of how AI lowers barriers for less mature operators while still enabling effective campaigns and evasion improvements. Separate technical reporting identified code-pattern similarities between FunkSec samples and RALord ransomware, suggesting possible code reuse, collaboration, or shared developer lineage, but the exact relationship remains unresolved. Known aliases are limited to FunkSec. The actor has also been linked in reporting to the persona Sentap, also known as Zestix, described as an initial access broker and data extortionist associated with the group, but that linkage pertains to an affiliated persona rather than a confirmed formal alias for the group itself.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat group referenced as using an AI assistant for malware development.
Ransomware-as-a-service operations using generative AI to develop ransomware, create variants, and automate victim negotiations.
Conducting persistent ransomware campaigns targeting the higher education sector.
Prolific financially motivated ransomware threat affecting schools and universities globally during the reporting period.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.