Funksec Ransomware Teams Up with Another Ransomware Group to Double Down on Targets


FunkSec is a relatively new but highly active ransomware group that, as of this writing, has targeted several dozen victims across industries like government, banking, communications, and education. In a recent blog post, the group announced a partnership with another ransomware outfit, FSociety, aiming to carry out attacks more efficiently.

This week, SonicWall Capture Labs research team analyzed the group’s malware, known as FunkLocker ransomware. Interestingly, rather than demanding massive payouts, FunkSec typically requests just 0.1 Bitcoin. This suggests they may be pursuing a “churn and burn” strategy — favoring a quick turnover approach to rapidly generate revenue.

Read more…
Source: SonicWall 


Sign up for our Newsletter


Related:

  • Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline

    August 17, 2026

    Rapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing scripts, fake wallet applications, persistence mechanisms, and Telegram exfiltration code. Among the artifacts was evidence that the operator relied on AI coding assistants throughout the ...

  • McDonald’s, Vodafone, TCS, Kyndryl, and others named as researchers point to compromised credentials

    August 17, 2026

    A cybercrook claims to have siphoned millions of employee records from the Microsoft Azure environments of major companies including McDonald’s, Vodafone, Kyndryl, and Tata Consultancy Services. The alleged haul spans nine organizations and is being advertised for sale by a threat actor using the name “TheHatman,” according to research published by Hudson Rock. McDonald’s accounts for the largest ...

  • ChainDrop worm crawls into npm supply chain, evades standard defenses

    August 15, 2026

    A new variant of the Shai-Hulud npm worm has poisoned hundreds of packages while adding propagation techniques that can leave little trace in the corresponding source repositories. In Frank Herbert’s Dune, Shai-Hulud was the name of the giant self-sustaining desert sandworms that moved silently beneath the surface of the planet Arrakis. So it made sense that when ...

  • APT group HoneyMyte upgrades CoolClient

    August 14, 2026

    CoolClient is a backdoor family attributed to the HoneyMyte APT group (also known as Mustang Panda) that has been used in their cyber-espionage campaigns targeting organizations across Asia and Russia. It supports such capabilities as keylogging, clipboard theft, credential harvesting, file management, system reconnaissance, and plugin-based extensions. Since its first public disclosure by Sophos in 2022 and subsequent ...

  • New Android malware lets criminals use your bank card in real time

    August 13, 2026

    Researchers at Group-IB have discovered a new NFC relay malware family, purpose-built to capture live card data via NFC and forward it in real time to attackers. They dubbed it “WindRelay.” NFC (Near Field Communication) is wireless technology that allows devices such as smartphones, payment cards, and payment terminals to communicate when they’re very close together. So, ...

  • Armored Likho expands its cyber-espionage toolkit

    August 13, 2026

    In May 2026, Kaspersky researches discovered a new cyber-espionage campaign by the Armored Likho group, also known as Eagle Werewolf, that targets private individuals and organizations across various industries in Russia, including major corporations, the public sector, IT, and education. The attackers used a fake app as bait that mimics a service for donations. However, ...