Deep Dive Into Allegedly AI-Generated FunkSec Ransomware
Essential information
- Published
- 04/03/2025 03:59
- Modified
- 04/03/2025 09:31
- Tags
- 2025-03-04 ai-generated anti-vm evasion techniques funksec persistence ransomware
- Related entities
- 1 observables, 1 techniques (mitre), 1 malware
Description
A new Rust-based ransomware called FunkSec has emerged, claiming to use artificial intelligence in its development. First appearing in 2024, it demonstrates a mix of sophisticated capabilities and developmental inconsistencies. FunkSec implements advanced features like XChaCha20 encryption and comprehensive anti-VM techniques, but also shows peculiarities such as dependency on downloading a specific wallpaper image. The malware disables Windows security features, establishes persistence via scheduled tasks, and targets multiple file extensions. It employs various evasion techniques, including disabling event logging and real-time protection. The ransomware's execution reveals technical anomalies, suggesting it may still be in development and could evolve further.