FunkSec is a ransomware group/RaaS operation that emerged in late 2024 and briefly became one of the most prolific ransomware actors worldwide. It is described as financially motivated, while also blurring the line with hacktivism; reporting notes some activity aligned with political themes such as "Free Palestine." The group has been linked in reporting to actors associated with Algeria, and one report linked the persona Sentap/Zestix to FunkSec and assessed that persona as likely Iranian, but the available content does not establish a definitive state affiliation for FunkSec itself. FunkSec uses double extortion, combining data exfiltration with file encryption, and has claimed large victim volumes, including more than 85 victims in December 2024 alone and 172 victims overall in one cited dataset. The vast majority of claimed victims were in the United States, India, and Brazil, with technology, government, and education among the top targeted sectors. Separate reporting noted 12 claims involving government agencies, with only one confirmed. Universities were specifically cited as facing persistent ransomware campaigns from groups including FunkSec. The group is notable for unusually heavy use of AI/LLM-assisted tooling despite apparently limited technical proficiency. Multiple sources state that much of its tooling was AI-generated or AI-refined, and that FunkSec used LLMs in its tooling, AI-created phishing templates, and WormGPT. Reporting also states that the group integrated AI-powered phishing template generation into affiliate/service offerings and used a rudimentary AI/LLM-developed encryptor to support later platforms including FunkBID and FunkForum. Its ransomware has been described as Rust-based and using the ChaCha20 cipher. Reported behavior includes disabling Windows Defender and event logging, deleting Volume Shadow Copies, checking for administrative privileges, terminating a hardcoded list of processes and services before encryption, renaming encrypted files with the .funksec extension, and dropping a ransom note directing victims to pay 0.1 BTC and communicate via Session. The group has been described as demanding unusually low ransoms, sometimes as low as $10,000. FunkSec also provided or distributed additional offensive tooling beyond ransomware, including homegrown DDoS tools. Specifically cited tools include FDDOS, a Python-based DDoS tool; JQRAXY_HVNC, a C++ HVNC tool; and funkgenerate, a credential scraping/generation tool. Reporting characterizes the group as offering not only ransomware but also the tools used to conduct attacks. Known aliases and related names directly mentioned in the content include funksec/FunkSec. Related personas and associated names mentioned in reporting include Scorpion (DesertStorm), El_Farado, and Sentap/Zestix. The group reportedly ceased activity in March 2025.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting persistent ransomware campaigns targeting the higher education sector.
Prolific financially motivated ransomware threat affecting schools and universities globally during the reporting period.
Cybercriminal ransomware group noted for rapidly scaling operations despite limited technical proficiency, reportedly using AI-generated attack tooling.
Referenced as integrating AI-powered phishing template generation and LLM-backed tooling into affiliate service offerings.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.