Funksec Ransomware Teams Up with Another Ransomware Group to Double Down on Targets


FunkSec is a relatively new but highly active ransomware group that, as of this writing, has targeted several dozen victims across industries like government, banking, communications, and education. In a recent blog post, the group announced a partnership with another ransomware outfit, FSociety, aiming to carry out attacks more efficiently.

This week, SonicWall Capture Labs research team analyzed the group’s malware, known as FunkLocker ransomware. Interestingly, rather than demanding massive payouts, FunkSec typically requests just 0.1 Bitcoin. This suggests they may be pursuing a “churn and burn” strategy — favoring a quick turnover approach to rapidly generate revenue.

Read more…
Source: SonicWall 


Sign up for our Newsletter


Related:

  • How legitimate cloud platforms enable phishers to bypass MFA

    August 4, 2026

    Threat actors are increasingly exploiting legitimate cloud services to evade detection and streamline the deployment of their scam infrastructure. Cloud hosting services and decentralized networks have become primary platforms for hosting phishing pages and sites. Throughout 2025 and 2026, Kaspersky researchers have observed phishing operators steadily migrate toward platforms like Cloudflare Workers, Vercel, Netlify, GitHub ...

  • Over 100,000 UK Police and staff have personal data leaked in attack on national database

    August 4, 2026

    The UK’s Police National Legal Database (PNLD) suffered a cyberattack recently, in which it allegedly lost sensitive data on more than 100,000 criminal justice professionals. In a short press release, PNLD confirmed the breach, saying it happened over a weekend. The threat actors, which were not named in the announcement, were said to have taken names, organizations, and ...

  • Hackers steal over $130M by exploiting bug in offline hardware wallets

    August 4, 2026

    Hackers are in the midst of a massive theft of cryptocurrency from supposedly secure offline hardware wallets, according to blockchain security firms monitoring the heists. At least a dozen different hackers are said to be targeting Bitcoin owners who use the hardware crypto wallet Coldcard, made by Coinkite. At this point, it’s unclear who is behind ...

  • Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

    August 3, 2026

    This article analyzes new attack classes against passwordless authentication, focusing on Google’s synced passkey ecosystem and the Cloud Authenticator used by desktop clients. The attacks demonstrate how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to take over passkey-protected accounts. Palo Alto Unit 42 shows how an attacker can authenticate ...

  • INTERPOL report finds AI linked to more than half of cybercrime in Africa

    August 3, 2026

    Artificial intelligence is enabling 55 per cent of reported cybercrimes across Africa making attacks faster, more scalable, and increasingly difficult for victims and platforms to detect, according to INTERPOL’s African Cyberthreat Assessment Report 2026. With more than 1.1 billion mobile subscribers recorded in 2025, Africa’s digital transformation is expanding rapidly. However, cybercrime legislation is fragmented and AI readiness ...

  • An analysis of incidents at Brazilian educational institutions

    August 3, 2026

    Because of the amount of data that can be obtained and the high impact that successful attacks may have, educational institutions are frequent targets of cybercriminals. Both public and private schools and universities rely on software for managing personally identifiable information (PII) that is often insecure or insufficiently tested against known vulnerabilities. In addition, machines ...