Silent Ransom Group is a financially motivated cyber extortion actor active since at least 2022 and widely tracked as UNC3753, Luna Moth, Chatty Spider, SRG, and Silent Ransom. The group is associated with data-theft extortion rather than traditional encryption-led ransomware operations, relying heavily on social engineering to obtain access, steal sensitive information, and pressure victims into paying to prevent disclosure. The actor has conducted sustained campaigns against U.S. law firms and other professional and financial services organizations, with reporting indicating especially aggressive activity from January through May 2026 and continued targeting of high-profile legal-sector victims thereafter. Victimology consistently centers on organizations holding confidential legal, financial, and personally identifiable information, making legal services a particularly prominent target set. Silent Ransom Group commonly initiates intrusions with benign pretext emails, often invoice-themed, followed by voice phishing calls in which operators impersonate internal IT staff, help desks, or third-party support personnel. The group persuades targets to join screen-sharing sessions and install legitimate remote monitoring and management tools, then rapidly searches local systems, network drives, cloud storage, and document management platforms for high-value files. Reported tooling and tradecraft include use of commercial remote access software, staging of collected files, and exfiltration through common transfer utilities, browser uploads, and cloud storage services. Extortion demands are typically issued shortly after exfiltration and threaten disclosure to clients, employees, journalists, regulators, or publication on a leak site. A notable escalation in this actor’s operations is the use of in-person social engineering. Multiple reports and law-enforcement warnings state that individuals linked to the group have appeared at victim offices while posing as IT personnel or technicians, seeking endpoint access to copy data to removable media. Separate reporting also indicates recruitment of local gig workers to approach victims under help-desk-related pretexts and induce insertion of removable media into corporate systems. The group’s operational profile emphasizes speed, deception, and abuse of trusted workflows over malware-first intrusion tradecraft. Observed behaviors include credential theft, initial access through phishing and vishing, persistence via remote management tools, reconnaissance of enterprise file repositories, exfiltration of sensitive data, and defense evasion through use of legitimate software and trusted communication channels. Silent Ransom Group is also cited by some researchers as a likely offshoot or successor ecosystem element linked to former Conti personnel, although the actor is primarily distinguished by its social-engineering-led extortion model.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
378 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack resulting in a data breach against Mayer Brown, a US-based law firm in the professional services sector.
Mentioned only as a comparison/reference for fake IT support and extortion-related remote-access incidents, not as part of the SMOKE#SCREEN activity itself.
Conducting a ransomware attack resulting in a data breach against Moses & Singer LLP.
Data-theft-focused extortion group targeting high-profile law firms, using social engineering and even physical infiltration to gain access and exfiltrate sensitive legal records for extortion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.