FunkSec
FunkSec is a Rust-based ransomware family and associated extortion operation that emerged in late 2024.
Profile source: Mallory opens in a new tabFunkSec
Family profile
FunkSec is a Rust-based ransomware family and associated extortion operation that emerged in late 2024. It encrypts victim files using the orion-rs cryptographic library with ChaCha20 and Poly1305, changes the desktop wallpaper to present a ransom message, and has been associated with double-extortion activity. Observed variants attempted to impair recovery and endpoint defenses by deleting volume shadow copies and disabling Microsoft Defender through PowerShell and system-configuration changes. Multiple researchers assessed that its development was partially assisted by large language models; rapid naming changes and unusually structured code have been cited as supporting evidence. The operation claimed victims predominantly in the United States, India, and Brazil, with technology, government, and education among the most frequently affected sectors. It ceased adding victims to its leak site in March 2025 and is regarded as inactive. A free decryptor is available through the No More Ransom project.
Capabilities
- Defense Evasion
- Extortion
Operational record
MITRE ATT&CK