Site navigation

AI-assisted Ransomware Group Claims 85 Victims in December

Staff Writer

,

AI ransomware
The FunkSec ransomware gang has rapidly emerged as a significant threat by utilising AI tech, despite the apparent inexperience of its members.

Cybersecurity researchers have uncovered an emerging ransomware group which allegedly uses AI-assisted malware, and claimed 85 victims in December alone – more than any other ransomware group.

According to a report from Check Point Research, the FunkSec group straddles the line between hacktivism and cyber-crime, presenting itself as a Ransomware-as-a-Service (RaaS) operation, but appears to have no known connections to previously identified ransomware gangs, with little information known about its origins.

The researchers claim that analysis of FunkSec’s code points to inexperienced malware authors, possibly from Algeria, with AI being leveraged to enhance their capabilities. 

Messages published by members of the group specifically link the creation of their ransomware to AI agents allowing for the rapid evolution of custom malware, with an AI chatbot developed by FunkSec seemingly being designed solely to support malicious activities.

Check Point researchers said that the gang has recently begun to offer new versions of its malware, typically published just days apart, while boasting about its low detection rate, fuelling more speculation about how the group creates the malware.

According to the report, the group emerged without warning late last year, and quickly dominated the ransomware scene, gaining visibility for a flurry of attacks predominantly targeting India and the US, as well as aligning with the ‘Free Palestine’ movement.

FunkSec gained further notoriety following attacks with unusually low ransom demands, sometimes as little as $10,000 (£8,226), with offers to sell stolen data to third-parties at reduced prices.

However, Check Point raised doubts about the authenticity of the group’s disclosures, with evidence suggesting that many of FunkSec’s leaked datasets are recycled from previous hacktivism campaigns.

Despite public claims attempting to link the new group to more established but now defunct hacktivist groups, evidence from Check Point suggests that FunkSec is being operated by those without much hacking experience.

One member of the group reportedly posted occasional threads on hacking forums asking ‘basic’ hacking questions, such as ‘What do hackers do with leaked data?’, while another shared compromising screenshots that revealed their location. 


Recommended reading


“FunkSec’s operations highlight the role of AI in malware development, the overlap between hacktivism and cyber-crime, and the challenges in verifying leaked data,” said Check Point researchers.

“It also raises questions about how we assess the threat posed by ransomware groups, as we often rely on the groups’ own claims. These findings reflect a changing threat landscape, where even low-skill actors can make use of accessible tools to cast a very large shadow.”

DIGIT Staff Writer Robot

Staff Writer

Staff Writer - DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data