HomeSecurityFunkLocker Ransomware Leverages AI and Windows Tools

FunkLocker Ransomware Leverages AI and Windows Tools

A new ransomware, dubbed FunkLocker, leverages artificial intelligence (AI) to accelerate its development, while relying on the abuse of legitimate Windows tools to disable security defenses and disrupt systems.

Ransomware FunkLocker AI Windows

FunkLocker ransomware: Exploiting AI

The ransomware, attributed to a group known as FunkSec, highlights a growing trend of malicious actors using artificial intelligence to compose malware (with varying degrees of success). FunkLocker’s development appears to follow a “Ask AI → Paste snippet” model, resulting in code that is often inconsistent. While some versions of the ransomware are barely functional, others incorporate more advanced features, such as checks against virtual machines.

This AI-assisted approach allows for rapid creation, but sacrifices the stability and complexity seen in malware from more established groups. These ransomware must be analyzed in secure Sandbox environments.

See also: Chinese 'Phantom Taurus' targets organizations with Net-Star

When executed, FunkLocker aggressively terminates a predefined list of processes and services. It uses standard Windows command-line tools, such as taskkill.exe to kill applications and sc.exe to stop services. This brute-force method often generates numerous errors as it attempts to kill non-existent or protected services, but ultimately succeeds in crippling the system's defenses and applications.

Abuse of Windows services

The list of targeted services includes security tools such as Windows Defender and Windows Firewall , as well as core system components such as Shell Experience Host , which causes the victim's screen to turn black. According to ANY.RUN 's sandbox analysis , FunkLocker heavily abuses PowerShell to systematically dismantle security measures. It executes a series of commands to disable real-time monitoring in Windows Defender , clean up security and application logs using wevtutil , and override PowerShell's execution policy to allow unrestricted script execution.

FunkLocker Ransomware Leverages AI and Windows Tools

To prevent system recovery, the ransomware uses the Volume Shadow Service Administrator (vssadmin.exe) to delete all shadow volume copies. This action removes the victim's ability to restore their system from local backups, a common technique used by ransomware to increase pressure on the victim.

See also: MatrixPDF: New kit turns PDFs into phishing and malware baits

The encryption is performed entirely locally, meaning that FunkLocker does not communicate with a command and control (C2) server to retrieve encryption keys. Files are encrypted and the .funksec extension is added.

A ransom note is then left on the desktop. However, because the malware often terminates the Shell Experience Host service, victims may not be able to see the note without restarting the compromised system.

Despite its disruptive capabilities, FunkLocker shows signs of poor operational security. Researchers have observed the reuse of Bitcoin wallet across different victims, and analysis suggests that the encryption keys are either embedded in the malware or originate locally on the victim's machine.

These vulnerabilities have allowed security researchers at Avast Labs to develop and release a public decryption tool, offering a recovery path for victims. Since its emergence in late 2024, the FunkSec group has been linked to attacks on more than 120 organizations worldwide. The group maintains a data leak website where it publishes stolen information. Targets span a variety of sectors, including government agencies, defense, technology, and financial companies. Most victims are located in the United States, with reports also from India, Spain, and Mongolia.

See also: Android banking trojan uses VNC server to remotely control devices

FunkLocker Ransomware Leverages AI and Windows Tools

Ransomware protection

  • Stay up to date on the latest ransomware trends and tactics used by attackers
  • Implement multi-factor authentication (MFA) for all user accounts
  • Enable firewall on all devices connected to your network
  • Keep sensitive data encrypted
  • Update all your devices and systems with the latest security patches
  • Conduct regular security audits and penetration testing
  • Use strong, unique passwords and change them regularly.
  • Limit user access to only necessary systems and information
  • Consider using  email security solutions for additional protection against phishing attacks
  • Have a recovery plan to quickly restore systems in the event of an attack
  • Enable the display of file extensions
  • Invest in advanced protection solutions
  • Use sandboxing for email attachments
  • Keep backup copies of your data
Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS