FunkSec is a ransomware family operated by the FunkSec ransomware-as-a-service group, which emerged in late 2024. The malware is described as a Rust-based encryptor that uses double extortion, combining data exfiltration with file encryption. It uses the ChaCha20 cipher, reportedly via the orion.rs crate, and generates ephemeral keys through a wrapper around the Windows API CryptGenRandom (SystemFunction036). Before encryption, it disables Windows Defender and event logging, deletes Volume Shadow Copies, checks for administrative privileges and relaunches itself with elevation if needed, and terminates a hardcoded list of processes and services including browsers, system tools, and communication applications. Encrypted files are renamed with the .funksec extension. A ransom note is dropped instructing victims to pay 0.1 BTC and contact the operators via the Session app.
The malware is associated with the FunkSec RaaS operation, which claimed high victim volume and unusually low ransom demands, often around $10,000. Reporting states the group targeted entities in the United States and India and at times aligned its messaging with political themes such as "Free Palestine," blurring hacktivist branding with financially motivated extortion. The group also operated a data leak site established in December 2024 and sold stolen data at reduced rates. Additional tools attributed to the broader operation include FDDOS, a Python-based DDoS tool; JQRAXY_HVNC, a C++ HVNC tool; and funkgenerate, a credential scraping/generation tool.
Multiple sources cited in the content state FunkSec showed signs of low technical sophistication and operational security failures, while also extensively leveraging LLM-assisted development. Researchers noted unusually well-documented code in perfect English and reported that operators used custom AI chatbots and provided source code to AI agents to accelerate malware and communication development. Attribution in the cited reporting links core FunkSec personas to Algeria, including actors referred to as Scorpion (DesertStorm) and El_Farado.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Rust-based ransomware used by the FunkSec RaaS group, employing double extortion (data exfiltration and encryption), low ransom demands, and LLM-assisted development. It disables security controls, terminates processes, encrypts files with ChaCha20, and appends a .funksec extension. Supplementary tools include DDoS, HVNC, and credential scraping utilities.
FunkSec ransomware is a Rust-based ransomware family that shows evidence of being developed or refined using large language model (LLM) agents, resulting in well-documented code and rapid development cycles.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.