FunkSec is a Rust-based ransomware family and associated extortion operation that emerged in late 2024 and was active into early 2025. The group conducted double-extortion activity, combining file encryption with data-leak pressure through a leak site, and claimed a large number of victims before going inactive. Reported victim geography was concentrated in the United States, India, and Brazil, with technology, government, and education among the most affected sectors.
The malware encryptor uses ChaCha20 and Poly1305 via the orion-rs Rust cryptography library. Analyses have noted implementation overlap or code-pattern similarities with other Rust ransomware, including RALord, suggesting possible code reuse or shared development lineage, although common authorship is not established. FunkSec has also been cited as an example of ransomware apparently developed or refined with assistance from large language models, and researchers have characterized the operators as relatively inexperienced compared with more mature ransomware crews.
FunkSec has been associated with broader criminal tooling beyond ransomware, including provision of attack-enabling tools and homegrown DDoS capabilities. Reporting also links the group to AI-assisted phishing template generation. The operation was described as a closed group rather than a public ransomware-as-a-service platform. By mid-2025, no new victims had been posted for months, and a public decryptor became available, indicating the family was no longer considered active.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware strain (emerged late 2024) for which a free public decryptor was released after the group went dormant (per summary).
Ransomware family (late 2024) using double extortion (data theft + encryption) and described as AI-assisted.
Ransomware group/family mentioned as another source from which a scam/impersonator allegedly copied victim listings.
Referenced as an example of prior AI-generated malware linked to inexperienced threat actors; no functional details provided in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.