Silent Ransom Group is a financially motivated cyber extortion actor active since at least 2022 and widely tracked as Luna Moth, Chatty Spider, and UNC3753. The group is associated with the broader Conti cybercrime ecosystem and has shifted away from traditional ransomware deployment toward data-theft extortion, typically stealing sensitive information and threatening public disclosure rather than encrypting systems. The actor has heavily targeted U.S. law firms and has also targeted financial services and other professional services organizations. Its operations rely primarily on social engineering rather than exploit-driven intrusion tradecraft. Common initial access patterns include callback phishing and voice phishing in which operators impersonate internal IT help desk or support personnel, often using benign invoice-themed or service-related pretexts to induce trust. Victims are persuaded to join screen-sharing sessions and install legitimate remote monitoring and management tools, after which the actor rapidly searches for high-value data such as legal agreements, tax records, personally identifiable information, audit materials, and financial records. Observed tradecraft includes use of legitimate remote access and collaboration platforms, abuse of BYOD and virtual desktop workflows, staging of collected files prior to theft, and rapid exfiltration to attacker-controlled cloud storage or other external destinations. Extortion demands commonly follow shortly after exfiltration and threaten disclosure to employees, clients, journalists, regulators, or publication on the group’s leak infrastructure. Reporting also links the group to physical-world social engineering: when remote access attempts fail, individuals posing as IT technicians have reportedly sought in-person access to offices and endpoints to copy data to removable media. Separate reporting also describes recruitment of local gig workers to facilitate such physical access schemes. Silent Ransom Group is best characterized as an extortion-focused, identity- and trust-abuse-heavy actor whose operations center on credentialed access, remote management tooling, data theft, and coercive disclosure threats rather than malware-led encryption. The group has also been reported to use resilient leak-site infrastructure, including fast-flux techniques, to sustain extortion operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
378 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Data-theft-focused extortion group targeting high-profile law firms, using social engineering and even physical infiltration to gain access and exfiltrate sensitive legal records for extortion.
Listed only in the actor index/TTP section without substantive discussion.
Russian cyber extortion group conducting social-engineering-based extortion, including impersonating helpdesk staff, persuading victims to install remote management tools, and recruiting local gig workers to physically assist access by delivering USB devices to victims.
Referenced as another group conducting extortion-only campaigns based on stolen data and leak threats rather than file encryption.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.