Luna Moth, also known as Silent Ransom, is a financially motivated data-extortion operation active since 2022. It primarily targets professional-services organizations, particularly law firms, and has also targeted insurance-sector organizations. The operation relies on high-touch social engineering rather than technical exploitation for initial access. Operators commonly conduct callback phishing and voice-phishing campaigns while impersonating internal IT staff or third-party help desks, persuading victims to install legitimate remote-support software. This gives the operators interactive access to victim workstations, from which they collect sensitive information and subsequently threaten its disclosure for payment. Luna Moth has generally focused on individual workstations and avoided broad lateral movement, although campaigns have at times involved multiple workstations. Its activity is characterized principally as data-theft extortion rather than encryption-based ransomware, and large demands against law firms have been associated with the sensitivity of stolen legal records.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware/extortion operation associated in the reference with high-touch social-engineering tactics and significant payments by law firms.
Data-theft-focused extortion group that targets law firms, using social engineering, vishing, and even physical impersonation of IT personnel to gain access and steal sensitive legal records for extortion.
Silent Ransom, also known as Luna Moth, is a group that uses callback phishing and targets specific industries such as insurance and law firms, focusing on data exfiltration and extortion.
A social-engineering-driven extortion operation active since 2022 that impersonates IT support to trick employees into installing remote assistance tools, then steals sensitive data from a small number of workstations without broad lateral movement or operational disruption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.