Funksec Ransomware Teams Up with Another Ransomware Group to Double Down on Targets


FunkSec is a relatively new but highly active ransomware group that, as of this writing, has targeted several dozen victims across industries like government, banking, communications, and education. In a recent blog post, the group announced a partnership with another ransomware outfit, FSociety, aiming to carry out attacks more efficiently.

This week, SonicWall Capture Labs research team analyzed the group’s malware, known as FunkLocker ransomware. Interestingly, rather than demanding massive payouts, FunkSec typically requests just 0.1 Bitcoin. This suggests they may be pursuing a “churn and burn” strategy — favoring a quick turnover approach to rapidly generate revenue.

Read more…
Source: SonicWall 


Sign up for our Newsletter


Related:

  • Unpacking a new Horabot campaign in Mexico

    March 18, 2026

    In this instalment of Kaspersky SOC Files series, Kaspersky researchers will walk you through a targeted campaign that our MDR team identified and hunted down a few months ago. It involves a threat known as Horabot, a bundle consisting of an infamous banking Trojan, an email spreader, and a notably complex attack chain. Although previous research ...

  • Marquis says over 672,000 people had personal and financial data stolen in ransomware attack

    March 18, 2026

    Marquis, a technology company used by hundreds of banks to analyze and visualize their customers’ data, says hundreds of thousands of people had their personal and sensitive financial information stolen in a ransomware attack last year. The Plano, Texas-based fintech company is notifying at least 672,075 people that hackers stole their information during the August 2025 ...

  • Notorious online data leak market BreachForums taken down by whitehat heroes

    March 17, 2026

    BreachForums, one of the most popular underground forums for sharing malware, stolen data, and more – was taken down. Now, the admin seems to be giving up and looking for someone to pass the torch to. Over the weekend, the Cyber Counter-Intelligence Threat Investigation Consortium (CCITIC) posted on LinkedIn, saying that both the clearnet and Tor ...

  • EU sanctions Chinese and Iranian companies for cyber attacks

    March 16, 2026

    The European Union on Monday imposed sanctions against ‌two China-based and one Iranian ‌company for cyber attacks against EU member ​states. The EU listed China-based Integrity Technology Group and Anxun Information Technology, and Iranian company Emennet Pasargad. Integrity Technology ‌is seen ⁠to have enabled hacks of over65,000 devices across six member ⁠states, according to an EUstatement. ...

  • Interpol: 45,000 malicious IP addresses taken down in international cyber operation

    March 13, 2026

    LYON, France – An international cybercrime operation targeting phishing, malware and ransomware has taken down more than 45,000 malicious IP addresses and servers. Law enforcement from 72 countries and territories took part in Operation Synergia III (18 July 2025 – 31 January 2026), coordinated by INTERPOL. The operation led to the arrest of 94 people, with ...

  • Swedish government IT system hacked

    March 13, 2026

    A large amount of sensitive information allegedly coming from a Swedish government IT system has been posted on the darknet, according to Dagens Nyheter and Expressen. DN writes that the newspaper has taken note of the leak and that it appears to contain the source code for a digital identity management system used by several authorities. ...