216.73.216.6

Analysis: AI-powered Ransomware from APT Group

· Published 02/10/2025 07:43 · Modified 02/10/2025 08:15

Export JSON

Essential information

Published
02/10/2025 07:43
Modified
02/10/2025 08:15
Tags
2025-10-02 ai-assisted encryption funklocker powershell process-disruption ransomware system-abuse
Related entities
1 observables, 1 intrusion sets (apt), 6 techniques (mitre), 1 malware, 10 others

Description

, a strain developed by the FunkSec APT group, showcases the growing trend of malware creation. The exhibits inconsistent quality across multiple builds, with some versions incorporating advanced features like anti-VM checks. It aggressively disrupts system processes, abuses legitimate Windows utilities, and encrypts files locally without contacting a command-and-control server. FunkSec's operational security is weak, allowing researchers to develop a public decryptor. The group has compromised over 120 organizations worldwide, targeting sectors such as government, defense, technology, finance, and education. 's behavior maps to several MITRE ATT&CK techniques, including process termination, service stoppage, and inhibiting system recovery.

External references