Silent Ransom Group (SRG) is a Russian cyber extortion threat actor focused on pure data-theft extortion rather than traditional ransomware encryption. The group is widely tracked under the aliases Luna Moth, Chatty Spider, and UNC3753, and has been described as a Conti offshoot or successor-linked operation that emerged around 2022 after fragmentation in the Conti ecosystem. SRG specializes in social-engineering-led intrusions. Its hallmark tradecraft involves impersonating internal IT or help desk personnel through phishing, callback phishing, and voice-based social engineering to convince employees to install legitimate remote management or remote assistance software, thereby granting the attackers hands-on-keyboard access. Reporting indicates the group often limits activity to one or a small number of workstations and prioritizes rapid collection and exfiltration of sensitive files over broad lateral movement or disruptive encryption. In 2025, the group was also reported to have expanded into physical impersonation, including sending individuals to victim offices while posing as IT staff in order to obtain direct access to endpoints and removable-media-based access when remote methods fail. The group primarily targets U.S.-based organizations that hold highly sensitive or privileged information, especially law firms and other professional services firms. Additional targeting has included financial, insurance, and healthcare organizations. Its victimology reflects a preference for sectors where stolen legal, financial, regulatory, or client data can be used as high-leverage extortion material. SRG’s business model centers on stealing data and threatening public release unless payment is made. It is notable for conducting extortion without deploying an encryptor, making it a prominent example of the broader shift from ransomware to exfiltration-only extortion. The group has used leak-site pressure and direct victim communications to coerce payment. Industry reporting has also characterized SRG as one of the few e-crime groups to rely almost exclusively on social engineering for initial access over an extended period. Known aliases include Silent Ransom, Silent Ransom Group, SRG, Luna Moth, Chatty Spider, and UNC3753. The actor is associated with the post-Conti cybercrime landscape and is part of a broader trend in which former Conti-linked personnel dispersed into successor extortion and ransomware operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian cyber extortion group conducting social-engineering-based extortion, including impersonating helpdesk staff, persuading victims to install remote management tools, and recruiting local gig workers to physically assist access by delivering USB devices to victims.
Referenced as another group conducting extortion-only campaigns based on stolen data and leak threats rather than file encryption.
Referenced as a comparison point for pure data-theft extortion campaigns that do not deploy encryption.
Conducting cyber extortion campaigns against U.S. law firms and other legal, professional, and financial services organizations by stealing sensitive data and threatening public exposure rather than encrypting systems.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.