First identified in December 2024, FunkLocker ransomware is an AI-assisted threat developed by the FunkSec Group, operating under a Ransomware-as-a-Service (RaaS) model. Targeting Windows systems, the group has struck across multiple industries including government, defense, finance, and higher education, with victims reported in the United States, India, Spain, Mongolia, Italy, Brazil, and Israel.
FunkLocker encrypts files locally using RSA-2048 and AES-256 encryption, appending the “.funksec” extension to compromised data. Unlike many ransomware families, FunkLocker operates without command-and-control communication, relying solely on local encryption and demanding low ransoms (around 0.1 Bitcoin) to encourage fast payments. The FunkSec Group’s blend of cybercrime and hacktivism underscores the shift toward AI-enabled ransomware that prioritizes speed, stealth, and scalability.
FunkSec Group designed FunkLocker to execute attacks directly on victim machines without network dependencies. Once deployed, the ransomware terminates critical processes, disables antivirus and security tools, and prevents system recovery by misusing legitimate Windows utilities such as taskkill.exe, sc.exe, and PowerShell. This allows the ransomware’s activities to blend seamlessly with normal system operations.
After neutralizing defenses, FunkLocker encrypts all accessible files, appending the “.funksec” extension. Its offline encryption model makes detection through traditional network-based monitoring tools nearly impossible.
Researchers have determined that FunkLocker’s codebase is partially generated using artificial intelligence, enabling rapid creation of new variants but also introducing weaknesses such as hardcoded encryption keys and reused cryptocurrency wallets. These flaws have allowed some free decryption tools to emerge, though many organizations remain vulnerable.
To date, over 120 organizations have been impacted. The campaign shows an opportunistic pattern—targeting both public and private sectors—demonstrating how AI-driven malware automation is accelerating the pace and unpredictability of ransomware operations.
SHA256 Hashes
File Path
Recent Breaches