The Silent Ransom Group — also tracked as UNC3753, Luna Moth, and Chatty Spider — has been targeting U.S. law firms and other professional, financial, insurance, and healthcare organizations with data-theft extortion campaigns that rely on social engineering instead of file encryption. FBI alerts and Google Mandiant reporting say the actors send invoice-themed phishing emails and follow up with voice calls impersonating internal IT or help desk staff, persuading employees to join screen-sharing sessions or install legitimate remote management tools such as AnyDesk, Zoho Assist, Bomgar, Splashtop, Syncro, Atera, and SuperOps. Once inside, the group rapidly searches document repositories and cloud stores for legal files, tax records, financial data, PII, and other sensitive material, then exfiltrates it with tools including WinSCP, hidden or renamed Rclone, Google Drive, Microsoft OneDrive, or victim-controlled file-sharing channels.
Authorities said the campaign has escalated beyond remote access attempts to in-person intrusions, with imposters arriving at offices posing as technicians and connecting USB drives or external disks to steal data when remote social engineering fails. Mandiant said dozens of U.S. organizations were targeted between January and May, and in some cases the intrusion, theft, and extortion cycle was completed within a single business day, with ransom demands sent shortly after access ended. Researchers and the FBI linked the operation to the post-Conti cybercrime ecosystem and noted that its abuse of legitimate tools leaves few forensic artifacts, while Resecurity reported fast-flux infrastructure supporting leak sites including business-data-leaks[.]com and ep6pheij[.]com. The FBI and Google urged organizations to verify anyone claiming to be IT staff, restrict unauthorized remote management and VDI access, harden USB and removable-media controls, deploy phishing-resistant MFA, and closely monitor sensitive document systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
On 5 June 2026, Google Threat Intelligence Group published research on an ongoing campaign against U.S. law firms and assessed that attempted in-person data theft incidents likely overlapped with UNC3753 based on targeting, structure, and timing. The report also documented the group's use of remote monitoring tools, help-desk impersonation, and extortion-focused data theft.
Google Mandiant said UNC3753 targeted dozens of U.S. legal, financial, and professional services organizations between January and May 2026. The campaign relied on invoice-themed emails, vishing, screen sharing, and legitimate remote management tools to steal sensitive data and quickly extort victims.
On 26 May 2026, the FBI issued FLASH-20260526-01 warning that SRG was actively targeting U.S.-based law firms through phishing, fake IT support calls, and in some cases in-person access attempts. The alert detailed rapid data exfiltration and extortion activity and recommended stronger visitor verification, MFA, and restrictions on remote access and removable media.
Resecurity reported that it identified fast-flux infrastructure supporting SRG leak sites including business-data-leaks[.]com and ep6pheij[.]com. The report described rotating residential IPs, DNS changes, and tokenized links designed to make the actor's leak ecosystem more resilient to blocking and takedown.
A 23 May 2025 FBI and DHS/CISA private industry notification said that as of April 2025 SRG had shifted from callback phishing and remote-access abuse to phone impersonation of internal IT staff followed by sending someone onsite to insert a storage device and steal data. The notice warned that the group used legitimate tools and left few artifacts.
Google said the group changed tactics around March 2025, moving from earlier callback-phishing and billing-lure approaches toward impersonating internal IT help desk staff. This shift underpinned later vishing-led intrusions and remote management tool abuse.
Google Threat Intelligence Group described UNC3753, also known as Silent Ransom Group, Luna Moth, and Chatty Spider, as financially motivated and active since at least March 2022. Reporting also links the actor to the post-Conti ecosystem and a shift away from ransomware deployment toward pure data theft and extortion.
The FBI said SRG has consistently focused on U.S.-based law firms since spring 2023, while also targeting sectors such as finance, insurance, and healthcare. Multiple reports characterize the legal sector as a primary long-term focus because of the sensitivity of client and case data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
29 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityonline.info
Open sourceoccrp.org
Open sourcecodeby.net
Open sourcebrightdefense.com
Open sourceresecurity.com
Open sourceic3.gov
Open sourceic3.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.