Luna Moth, also tracked as Silent, Silent Ransom Group, Chatty Spider, and UNC3753, is a financially motivated cybercriminal extortion group active since at least 2022. The group is associated with callback-phishing and social-engineering operations and was initially linked to BazarCall-style activity connected to the broader Conti and Ryuk ecosystem before evolving into a standalone data-theft and extortion actor after Conti’s collapse. Luna Moth primarily targets organizations in the United States, with repeated reporting on campaigns against legal firms and prior targeting of legal and financial organizations. Its operations emphasize deception over malware-heavy intrusion chains. Typical initial access involves phishing emails or telephone calls impersonating internal IT or support personnel and persuading victims to grant remote access through RDP or other remote administration tools. In 2026, the group adopted an unusual escalation method in attacks on U.S. law firms: when remote access attempts failed, an accomplice posing as an IT worker visited victim offices in person, connected external storage media to a workstation, obtained access, escalated privileges, and exfiltrated data. The group generally favors encryption-less extortion. Rather than deploying file-encrypting ransomware, it steals sensitive data and threatens to publish or sell it unless payment is made. Reported tradecraft includes use of legitimate tools for transfer and staging, reliance on built-in administration capabilities to minimize forensic artifacts, and exfiltration to cloud storage services or removable media. Victim pressure tactics have included direct ransom demands as well as contacting employees and, in some cases, clients of victim organizations. Luna Moth has been observed at significant scale in 2026 and has been associated with high-value extortion demands against law firms. Its operational profile is characterized by social engineering, low-noise post-compromise activity, rapid privilege escalation, and data theft-driven extortion rather than disruptive encryption.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Rapidly emerging ransomware group that newly entered the top rankings by incident volume.
Data-theft and extortion operations targeting U.S. legal firms, using callback phishing, phone-based social engineering, remote access attempts, and in-person impersonation of IT staff to gain physical access and steal data without deploying ransomware encryption.
Named as the ransomware group that demanded $13 million in connection with a March 2026 data breach affecting Jones Day.
Ransomware group noted for a large ransom demand against a business-sector legal firm.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.