Threat Actor Characterization
You’re viewing the read-only version.
Sign in for analyst tools (editors, promote draft, file/relations management, etc.)
FunkSec
ID: 69cc5ffdc20c5e83a0f6b788a05a102963856
Crimeware
Botnet
Ransomware
Trojan
Threat types: Phishing, Data Leak, Ransomware, Malware
Progress: 89%
Completeness: 89%
Freshness: 90%
Operation zone: Algeria, Argentina, Australia, Bangladesh, Brazil, Colombia, Egypt, France, Germany, Italy, Jordan, Mexico, Mongolia, Pakistan, Paraguay, Spain, United States, Vietnam, Zambia
Aliases
Limited alias preview
| Funksec Group | — | — | — |
Actor Network Graph
Open Network GraphMITRE ATT&CK®
confidence: medium
FunkSec is an emerging ransomware-as-a-service (RaaS) brand (late 2024) using double extortion and a Rust-based encryptor often called FunkLocker; public reporting emphasizes AI-assisted development and mixed operational maturity.
| Technique | Technique name | Tactics | Evidence |
|---|---|---|---|
| T1486 | Data Encrypted for Impact | TA0040 | |
| T1490 | Inhibit System Recovery | TA0040 |
|
| T1566 | Phishing | TA0001 |
|
| T1078 | Valid Accounts | TA0001 TA0003 TA0004 TA0005 |
|
| T1041 | Exfiltration Over C2 Channel | TA0010 |
|
| T1562.001 | Disable or Modify Tools | TA0005 |
|
Executive brief
now
Saved successfully.
Hunting Playbook
now
Saved successfully.
IOC Appendix
now
Saved successfully.
OSINT Library
now
Saved successfully.