FunkSec is a financially motivated ransomware and data-extortion operation that emerged in late 2024. It has operated a dedicated leak site and has made victim claims across multiple sectors, notably technology, government, education, and healthcare. Its claimed victim activity has been concentrated in the United States, India, and Brazil. FunkSec has been associated with ransomware written or refined using large-language-model assistance, including Rust-based tooling, and has reportedly used generative AI to develop ransomware variants, phishing templates, and victim-negotiation chatbots. The group has also offered or used DDoS tooling alongside ransomware-related services. Some early FunkSec victim claims were assessed as unreliable or copied from other ransomware operations; victim postings should therefore not be treated as confirmation of compromise without independent validation. FunkSec was reported to have paused or disappeared during 2025.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat group referenced as using an AI assistant for malware development.
Ransomware-as-a-service operations using generative AI to develop ransomware, create variants, and automate victim negotiations.
Conducting persistent ransomware campaigns targeting the higher education sector.
Prolific financially motivated ransomware threat affecting schools and universities globally during the reporting period.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.