Silent is a cybercriminal extortion group associated with the aliases Silent Team, Silent Ransom Group, Luna Moth, Chatty Spider, and UNC3753. The actor has been active since at least 2022 and is widely characterized as an extortion-focused operation that often forgoes file encryption in favor of data theft and leak-based coercion. It emerged in ransomware tracking during 2024 and by 2026 had become a high-volume actor on leak-site reporting, including prominent activity against legal-sector victims. The group is known for social-engineering-heavy intrusion methods. Reported tradecraft includes phishing emails, callback phishing, and telephone impersonation of internal IT or support personnel to persuade targets to grant remote access through RDP or other remote administration tools. In a notable evolution observed in 2026, the operation reportedly escalated failed remote-access attempts by sending an accomplice to victim offices while posing as an IT worker, then using physical access and removable media to obtain access, escalate privileges, and steal data. The group is also reported to pressure victims after exfiltration by threatening publication or sale of stolen information and by contacting employees or clients directly. Silent typically relies on legitimate or built-in administration and transfer mechanisms to reduce forensic visibility and evade detection. Reported tooling and methods include use of remote administration utilities, living-off-the-land techniques, cloud storage services for exfiltration, and direct copying of stolen data to external media. The actor has been linked historically to BazarCall-style social engineering associated with the broader Conti and Ryuk ecosystem, and appears to have shifted after Conti’s collapse toward standalone data-theft extortion operations. Targeting has included U.S. legal organizations at high confidence, with broader victim reporting indicating activity against business victims in multiple countries and sectors. Silent has been described as conducting data-theft extortion rather than conventional locker-based ransomware in many incidents, although it is commonly tracked within the ransomware ecosystem due to its leak-site and ransom-demand operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Rapidly emerging ransomware group that newly entered the top rankings by incident volume.
Data-theft and extortion operations targeting U.S. legal firms, using callback phishing, phone-based social engineering, remote access attempts, and in-person impersonation of IT staff to gain physical access and steal data without deploying ransomware encryption.
Named as the ransomware group that demanded $13 million in connection with a March 2026 data breach affecting Jones Day.
Ransomware group noted for a large ransom demand against a business-sector legal firm.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.