THREAT LEVEL - MEDIUM

16-01-2025

Ransomware Group Leveraging AI

Threat Level Description

Threat Level: Medium – An attack is a strong possibility. Additional and sustainable protective security measures reflecting the broad nature of the threat combined with specific business and geographical vulnerabilities and judgments on acceptable risk.

Description

We have observed the emergence of a new ransomware group called FunkSec, which publicly appeared in late 2024 and quickly gained recognition by reporting over 85 alleged victims.

The group is believed to rely heavily on AI-assisted malware development, allowing rapid iteration of their tools despite limited technical expertise. This marks a growing trend of inexperienced actors leveraging AI tools to enhance their capabilities, further blurring the lines between hacktivism and cybercrime.

FunkSec has been observed using large language models to develop tools for Distributed Denial of Service (DDoS) attacks and to obfuscate malware in ways that bypass traditional security measures.

Additionally, the group offers Ransomware-as-a-Service (RaaS) to other criminal actors, significantly expanding the reach and impact of their operations.

Organizations must understand that AI-powered cyberattacks are an evolving threat that requires a comprehensive security strategy to mitigate. Implementing multi-layered defences and continuous monitoring is critical to reducing the risk of compromise

Recommendation(s)

We recommend that organizations take immediate proactive measures to defend against AI-driven ransomware attacks:

  • Implement anti-phishing solutions and train employees to recognize and report phishing attempts.
  • Utilize advanced solutions like ClearSkies Centric AI TDIR which incorporates AI-Driven Contextual Awareness to mitigate AI-born attack patterns.
  • Ensure all software and systems are up to date with the latest security patches.
  • Limit lateral movement within your network by segmenting critical assets and applying least privilege access.
  • Ensure that offline backups are regularly conducted and that restoration procedures are tested.
  • Stay informed about emerging threats and collaborate with threat intelligence providers to detect evolving tactics.
  • Perform regular penetration tests to uncover vulnerabilities and test your defences against evolving ransomware tactics.

References:

SIGN UP

Get the latest Threat Alerts in your inbox.