Skip to content

FunkSec

FunkSec is a Rust-based ransomware family and associated extortion operation that emerged in late 2024.

Profile source: Mallory opens in a new tab

FunkSec

Family profile

FunkSec is a Rust-based ransomware family and associated extortion operation that emerged in late 2024. It encrypts victim files using the orion-rs cryptographic library with ChaCha20 and Poly1305, changes the desktop wallpaper to present a ransom message, and has been associated with double-extortion activity. Observed variants attempted to impair recovery and endpoint defenses by deleting volume shadow copies and disabling Microsoft Defender through PowerShell and system-configuration changes. Multiple researchers assessed that its development was partially assisted by large language models; rapid naming changes and unusually structured code have been cited as supporting evidence. The operation claimed victims predominantly in the United States, India, and Brazil, with technology, government, and education among the most frequently affected sectors. It ceased adding victims to its leak site in March 2025 and is regarded as inactive. A free decryptor is available through the No More Ransom project.

Capabilities

  • Defense Evasion
  • Extortion

Operational record

1
YARA rules
11
Leak sites
2 available

MITRE ATT&CK

FunkSec in ATT&CK

6 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.