Threadlinqs IntelligenceStart free

Threat actorRussiaTracked since 2026-05

Luna Moth

Also known as:UNC3753Silent Ransom Group

As of 2026-08-28, Luna Moth is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 4 threats spanning ransomware, campaign. Also known as UNC3753, Silent Ransom Group. ATT&CK coverage spans 47 techniques across 14 tactics in 4 of 4 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1052.001 (Exfiltration Over Physical Medium: Exfiltration over USB), T1219 (Remote Access Tools).

Tracked threats
44 high
First seen
2026-05-28
Last seen
2026-08-28
ATT&CK techniques
47across 4 of 4 threats
Related CVEs
0None referenced
Attribution
RussiaNation or origin
Nation: Russia · 4 tracked threat(s) · Categories: RANSOMWARE, CAMPAIGN

Activity timeline

Luna Moth appears in 4 tracked threats between and ; the busiest month was 2026-08 with 2 reports.

ATT&CK techniques observed

47 techniques observed across 4 of 4 tracked threats · Initial Access (7), Reconnaissance (6), Execution (5), Exfiltration (5), Collection (4), Resource Development (4)
  • T1005 Data from Local System — Collectionobserved in 4 of 4 tracked threats
  • T1052.001 Exfiltration Over Physical Medium: Exfiltration over USB — Exfiltrationobserved in 4 of 4 tracked threats
  • T1219 Remote Access Tools — Command and Controlobserved in 4 of 4 tracked threats
  • T1566.004 Spearphishing Voice — Initial Accessobserved in 4 of 4 tracked threats
  • T1567.002 Exfiltration to Cloud Storage — Exfiltrationobserved in 4 of 4 tracked threats
  • T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 3 of 4 tracked threats
  • T1039 Data from Network Shared Drive — Collectionobserved in 3 of 4 tracked threats
  • T1135 Network Share Discovery — Discoveryobserved in 3 of 4 tracked threats
  • T1204.002 User Execution: Malicious File — Executionobserved in 3 of 4 tracked threats
  • T1583.001 Domains — Resource Developmentobserved in 3 of 4 tracked threats
  • T1657 Financial Theft — Impactobserved in 3 of 4 tracked threats
  • T1021.001 Remote Desktop Protocol — Lateral Movementobserved in 2 of 4 tracked threats
  • T1048.002 Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Prot — Exfiltrationobserved in 2 of 4 tracked threats
  • T1059.001 PowerShell — Executionobserved in 2 of 4 tracked threats
  • T1059.003 Windows Command Shell — Executionobserved in 2 of 4 tracked threats

Tracked threats