FunkSec is a ransomware and data-extortion group that emerged in late 2024 and operated as a Ransomware-as-a-Service ecosystem. The group rapidly became highly visible by claiming large numbers of victims and running a data leak site, while also offering or distributing supporting offensive tooling including a DDoS utility, remote-access tooling, and credential-focused utilities. Reporting consistently characterizes FunkSec as financially motivated, but with branding and messaging that at times borrowed from hacktivist themes, blurring the line between profit-seeking cybercrime and political posturing. FunkSec is notable for extensive use of generative AI and large language models in its operations. The group has been associated with AI-assisted ransomware development, generation of new variants, phishing template creation, and chatbot-style victim negotiation support. Multiple assessments describe the actor as having limited in-house technical depth and relying on AI-generated or AI-refined tooling to accelerate development and lower the skill barrier. Its ransomware tooling has been described as Rust-based and using ChaCha20 for file encryption. Observed behavior includes terminating targeted processes and services prior to encryption, disabling or impairing defensive controls, deleting shadow copies, checking for or seeking elevated privileges, and combining encryption with data theft for double extortion. FunkSec has also been linked to data auction and forum infrastructure used to monetize stolen information and build criminal visibility. Victimology indicates broad opportunistic targeting with especially strong concentration in the United States, India, and Brazil. Technology companies, government entities, and educational institutions have been repeatedly identified among the most affected sectors, and the group was also cited as a persistent ransomware threat to higher education globally. Government-focused reporting shows FunkSec made numerous claims against public-sector organizations, although some claims were unconfirmed. Separate reporting also places the actor among prolific ransomware groups during 2025. FunkSec has been associated with low ransom demands relative to many peers, aggressive publicity, and an emphasis on volume and notoriety over operational maturity. Some reporting also notes overlap between FunkSec and scam or impersonation activity in the ransomware ecosystem, including cases where other actors copied or reposted FunkSec victim claims. Code-pattern similarities have also been observed between FunkSec samples and later ransomware families, suggesting possible code reuse or shared development lineage. Attribution reporting links core FunkSec personas to Algeria, with named personas including Scorpion, also known as DesertStorm, and El_Farado. Overall, FunkSec is best understood as an Algeria-linked, financially motivated ransomware actor distinguished by AI-assisted tradecraft, double-extortion operations, broad opportunistic targeting, and comparatively uneven technical sophistication.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware-as-a-service operations using generative AI to develop ransomware, create variants, and automate victim negotiations.
Conducting persistent ransomware campaigns targeting the higher education sector.
Prolific financially motivated ransomware threat affecting schools and universities globally during the reporting period.
Cybercriminal ransomware group noted for rapidly scaling operations despite limited technical proficiency, reportedly using AI-generated attack tooling.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.