FunkSec is a Rust-based ransomware family and associated extortion operation that emerged in late 2024. It encrypts victim files using the orion-rs cryptographic library with ChaCha20 and Poly1305, changes the desktop wallpaper to present a ransom message, and has been associated with double-extortion activity. Observed variants attempted to impair recovery and endpoint defenses by deleting volume shadow copies and disabling Microsoft Defender through PowerShell and system-configuration changes. Multiple researchers assessed that its development was partially assisted by large language models; rapid naming changes and unusually structured code have been cited as supporting evidence. The operation claimed victims predominantly in the United States, India, and Brazil, with technology, government, and education among the most frequently affected sectors. It ceased adding victims to its leak site in March 2025 and is regarded as inactive. A free decryptor is available through the No More Ransom project.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family linked by multiple researchers to LLM-assisted development. Embedded project filenames showed rapid iteration through multiple names, which Unit 42 assessed as consistent with prompt-driven generation.
Ransomware strain with a common Rust codebase; observed disabling Windows Defender via PowerShell and registry changes, deleting volume shadow copies, and changing the desktop wallpaper to display a ransom note. The report suggests rapid variant iteration consistent with LLM-assisted development.
Ransomware strain (emerged late 2024) for which a free public decryptor was released after the group went dormant (per summary).
Ransomware family (late 2024) using double extortion (data theft + encryption) and described as AI-assisted.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.