Skip to content

FunkSec

FunkSec is a Rust-based ransomware family and associated extortion group that emerged in late 2024 and was first publicly observed around December 2024 to early 2025.

Profile source: Mallory opens in a new tab

FunkSec

Family profile

FunkSec is a Rust-based ransomware family and associated extortion group that emerged in late 2024 and was first publicly observed around December 2024 to early 2025. Reporting describes it as a closed operation rather than a public RaaS platform, although the group also advertised or provided additional offensive tooling, including homegrown DDoS tools, and has been described as openly using LLMs in parts of its tooling and phishing workflow. Multiple sources characterize the operators as relatively inexperienced and assess that the ransomware or related tooling shows signs of AI-assisted development or refinement.

FunkSec used double extortion tactics and maintained a leak site, with reporting variously stating it disclosed more than 85 victims, over 100 victims, and up to 172 claimed victims before going inactive. It reportedly stopped posting new victims after March 18, 2025, and researchers later considered the operation inactive or "dead." Victims were concentrated in the United States, India, and Brazil, and targeted sectors explicitly mentioned include technology, government, and education; other reporting places FunkSec among groups focusing on small- and mid-sized organizations.

The malware is written in Rust and uses the orion-rs library version 0.17.7 with ChaCha20 and Poly1305 for encryption. Reported implementation details include encryption in 128-byte blocks, addition of 48 bytes of metadata per encrypted block, and resulting encrypted files being about 37% larger than the originals. A hash-based method is used to ensure integrity of encryption parameters. Victims can identify affected files by the .funksec extension and unique metadata padding. One source also attributes intermittent encryption and sophisticated code obfuscation to FunkSec, describing these features as helping bypass traditional security controls.

The group has been repeatedly cited as an example of AI-assisted or AI-generated malware. Check Point and other researchers reported signs that the encryptor was developed with assistance from AI tools, while other commentary states the group used AI-generated phishing templates and that its Rust-based ransomware showed signs of being written or refined with LLM agents. Avast/Gen Digital released a free decryptor for FunkSec through the No More Ransom project, allowing victims to recover files without paying; administrators are advised to back up encrypted files before attempting decryption.

Operational record

1
YARA rules
7
Leak sites
2 available

MITRE ATT&CK

FunkSec in ATT&CK

1 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.