Skip to main content
Mallory
Back to intelligence
ransomware-group-operationvoice-social-engineeringdata-exfiltration-methodphishing-campaign-intelligence

FBI warns Silent Ransom Group is infiltrating US law firms through fake IT support

Updated 16h agoFirst seen May 27, 202620 sources

The FBI has warned that the Silent Ransom Group (SRG) — also tracked as Luna Moth, Chatty Spider, and UNC3753 — is actively targeting U.S. law firms with social-engineering campaigns designed to steal sensitive data for extortion. According to the bureau, the group uses callback phishing emails, fake IT support phone calls, and in some cases even in-person visits to offices while impersonating internal technology staff. Rather than encrypting systems, SRG focuses on gaining remote desktop or physical access, quickly exfiltrating files, and then threatening to publish or sell the stolen information on its leak site, including business-data-leaks[.]com.

Federal officials said the activity has consistently targeted U.S. law firms since spring 2023, while also affecting organizations in healthcare, insurance, and finance. The intrusions are difficult to detect because the attackers rely on legitimate remote administration and file-transfer tools and trusted cloud services, including WinSCP, Rclone, Google Drive, and Microsoft OneDrive, leaving few traditional malware artifacts behind. The FBI urged organizations to verify IT personnel and office visitors, harden help desk and password-reset procedures, enforce phishing-resistant MFA, restrict unauthorized remote access tools and removable media, and report related phishing emails, ransom notes, wallet details, and impersonator information to investigators.

Share:
FBI warns Silent Ransom Group is infiltrating US law firms through fake IT support
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Jun 5, 20262d ago

Google reports UNC3753 targeted dozens of U.S. firms across sectors

In a report published on 2026-06-05, Google/Mandiant said UNC3753 targeted dozens of U.S. banks, law firms, and professional services firms between January and May using social engineering, data theft, and extortion. The report said the group shifted toward fake help-desk impersonation around March 2025 and published indicators of compromise and defensive recommendations.

If you don't fall for these extortionists' calls, they'll show up with USB sticks

GTIG links physical office intrusions to UNC3753

In a report published on 2026-06-05, Google Threat Intelligence Group assessed that attempted in-person data theft incidents at U.S. law firms were likely connected to UNC3753, also known as Silent Ransom Group/Luna Moth. GTIG said the assessment was based on structural, timeline, and targeting overlaps, while noting limited forensic evidence prevented formal attribution.

Ongoing Targeted Campaign Against US Law Firms | Google Cloud Blog
May 27, 202611d ago

Silent Ransom Group begins sustained targeting of U.S. law firms

The FBI said the Silent Ransom Group, also known as Luna Moth, Chatty Spider, and UNC3753, has consistently focused on U.S. law firms since Spring 2023. The group uses social engineering to obtain remote or physical access, steal data, and extort victims without deploying file-encrypting ransomware.

FBI warns extortion hackers are visiting US law firms to steal data | The Record from Recorded Future News
May 26, 202612d ago

FBI issues FLASH warning on SRG attacks against law firms

On 2026-05-26, the FBI issued FLASH-20260526-01 warning that Silent Ransom Group is actively targeting U.S.-based law firms through callback phishing, fake IT support interactions, and in some cases in-person visits. The advisory described the group's use of legitimate tools and cloud services for rapid data exfiltration and requested victim reporting artifacts.

Ic3 Alerts
Feb 22, 20263mo ago

Resecurity uncovers SRG fast-flux leak-site infrastructure

On 2026-02-22, Resecurity reported that it had identified Silent Ransom Group's fast-flux DNS infrastructure supporting its leak sites, including rotating residential IPs, WebNic-registered domains, and tokenized download links designed to resist takedowns and analysis. The report also linked the newer Spy Corporate project to the same infrastructure ecosystem.

Resecurity | Silent Ransom Group (SRG): Uncovering DNS Fast Flux Infrastructure
May 23, 20251y ago

FBI and CISA issue private warning on SRG targeting law firms

On 2025-05-23, the FBI, with DHS/CISA, issued a TLP:CLEAR Private Industry Notification warning that Silent Ransom Group was targeting U.S.-based law firms. The notice said the group had shifted as of April 2025 to phone-based IT impersonation and, in some cases, sending someone on-site to insert a storage device and steal data.

Ic3 Alerts
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.