# Luna Moth

> As of 2026-08-28, Luna Moth is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 4 threats spanning ransomware, campaign. Also known as UNC3753, Silent Ransom Group. ATT&CK coverage spans 47 techniques across 14 tactics in 4 of 4 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1052.001 (Exfiltration Over Physical Medium: Exfiltration over USB), T1219 (Remote Access Tools).

- **Nation:** Russia
- **Tracked threats:** 4
- **Categories:** RANSOMWARE, CAMPAIGN
- **Also known as:** UNC3753, Silent Ransom Group
- **As of:** 2026-08-28

## ATT&CK techniques observed

47 techniques observed across 4 of 4 tracked threats. Tactics: Initial Access (7), Reconnaissance (6), Execution (5), Exfiltration (5), Collection (4), Resource Development (4).

- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 4 of 4 tracked threats
- [T1052.001](https://attack.mitre.org/techniques/T1052/001/) Exfiltration Over Physical Medium: Exfiltration over USB — Exfiltration — observed in 4 of 4 tracked threats
- [T1219](https://intel.threadlinqs.com/technique/T1219) Remote Access Tools — Command and Control — observed in 4 of 4 tracked threats
- [T1566.004](https://intel.threadlinqs.com/technique/T1566.004) Spearphishing Voice — Initial Access — observed in 4 of 4 tracked threats
- [T1567.002](https://intel.threadlinqs.com/technique/T1567.002) Exfiltration to Cloud Storage — Exfiltration — observed in 4 of 4 tracked threats
- [T1036.005](https://intel.threadlinqs.com/technique/T1036.005) Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 3 of 4 tracked threats
- [T1039](https://intel.threadlinqs.com/technique/T1039) Data from Network Shared Drive — Collection — observed in 3 of 4 tracked threats
- [T1135](https://intel.threadlinqs.com/technique/T1135) Network Share Discovery — Discovery — observed in 3 of 4 tracked threats
- [T1204.002](https://intel.threadlinqs.com/technique/T1204.002) User Execution: Malicious File — Execution — observed in 3 of 4 tracked threats
- [T1583.001](https://intel.threadlinqs.com/technique/T1583.001) Domains — Resource Development — observed in 3 of 4 tracked threats
- [T1657](https://intel.threadlinqs.com/technique/T1657) Financial Theft — Impact — observed in 3 of 4 tracked threats
- [T1021.001](https://intel.threadlinqs.com/technique/T1021.001) Remote Desktop Protocol — Lateral Movement — observed in 2 of 4 tracked threats
- [T1048.002](https://attack.mitre.org/techniques/T1048/002/) Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Prot — Exfiltration — observed in 2 of 4 tracked threats
- [T1059.001](https://intel.threadlinqs.com/technique/T1059.001) PowerShell — Execution — observed in 2 of 4 tracked threats
- [T1059.003](https://intel.threadlinqs.com/technique/T1059.003) Windows Command Shell — Execution — observed in 2 of 4 tracked threats

## Tracked threats

- [Silent Ransom Group (Luna Moth) Targets US Law Firms via IT Support Impersonation and Physical Intrusion](https://intel.threadlinqs.com/threat/TL-2026-2176) — HIGH
- [UNC3753 (Luna Moth / Silent Ransom Group) Vishing and Physical Intrusion Campaign Against US Law Firms](https://intel.threadlinqs.com/threat/TL-2026-2127) — HIGH
- [UNC3753 (Silent Ransom Group / Luna Moth) Escalation — Physical Office Intrusion & USB Data Exfiltration Against US Legal & Financial Services (FBI Flash CSA, 2026)](https://intel.threadlinqs.com/threat/TL-2026-0707) — HIGH
- [Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753) — IT Support Impersonation Campaign Targeting US Law Firms (FBI FLASH Advisory, May 2026)](https://intel.threadlinqs.com/threat/TL-2026-0612) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Luna%20Moth
