◇ SIGN IN
← all actors
ransomware

FunkSec

activemedium confidence
Ransomware
FunkSecFunkLocker
Attribution
Financially motivated with hacktivist framing (unattributed)
Origin
Unknown (operator assessed by Check Point as likely based in Algeria)
First seen
2024
Last active
2025
Motivation
Financially motivated (ransomware)
Confidence
medium
MENA targeting
Egypt
Sectors
Aviation

Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.

Why it mattersRansomware actor, medium confidence, documented targeting Egypt (Aviation sector).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

FunkSec is a ransomware-as-a-service operation that surfaced in late 2024, notable for its apparent use of AI-assisted malware development and a rapid, high-volume stream of extortion claims.

History

FunkSec emerged in late 2024 and quickly drew attention by claiming roughly 85 victims in December 2024, per Check Point Research. It presents as a RaaS using double extortion (data theft plus encryption) and mixes cybercrime with hacktivist messaging. Check Point assessed that some of its tooling — including a custom encryptor (FunkLocker), a DDoS tool, and utilities — was likely produced with AI assistance by a relatively inexperienced author assessed as likely based in Algeria, which may explain the group's rapid iteration.

By early 2025, FunkSec had been linked to 120+ claimed victims across government, defense, technology, financial services and higher education. Researchers have cautioned that the group's claim volume and low apparent sophistication mean many listings may be inflated, recycled, or partly fabricated.

FunkSec has claimed victims in Egypt among its listings. Given the noted reliability concerns, these leak-site claims should be treated as unverified allegations rather than confirmed breaches unless independently corroborated.

Notable campaigns

2024
December 2024 surge
FunkSec claimed roughly 85 victims in a single month, drawing Check Point's attention to an AI-assisted newcomer.
2025
AI-assisted tooling disclosure
Check Point assessed FunkSec's encryptor and tools were likely developed with AI assistance by an inexperienced author.
2025
Egypt leak-site claims
Egyptian organizations appeared among FunkSec's claimed victims (claimed, reliability uncertain).

Claimed victims · 172 tracked

Leak-site postings via ransomware.live — claimed by the group, not confirmed breaches. Metadata only. MENA Ransomware Watch →

DateVictimCountrySector
sorbonne-universite.frFREducation
semaphore.asso.frFRGovernment & Defense
extremeperformance.comUSRetail & E-Commerce
unimore.itITEducation
isee-eg.comEgyptTechnology
klabs.itITTechnology
univ-rennes.frFREducation
cimenyan.desa.idIDOther
mytower.com.brBRTechnology
stayzapp.inINHospitality
mandarin.com.brBRTechnology
rossmanmedia.aeUAETechnology