Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-05

Silent Ransom Group

Also known as:Luna MothChatty SpiderUNC3753Storm-0257TG2729Silent Ransom

As of 2026-08-28, Silent Ransom Group is a threat actor tracked by Threadlinqs Intelligence across 4 threats spanning ransomware, campaign. Also known as Luna Moth, Chatty Spider, UNC3753, Storm-0257. ATT&CK coverage spans 47 techniques across 14 tactics in 4 of 4 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1052.001 (Exfiltration Over Physical Medium: Exfiltration over USB), T1219 (Remote Access Tools).

Tracked threats
44 high
First seen
2026-05-28
Last seen
2026-08-28
ATT&CK techniques
47across 4 of 4 threats
Related CVEs
0None referenced
4 tracked threat(s) · Categories: RANSOMWARE, CAMPAIGN

Activity timeline

Silent Ransom Group appears in 4 tracked threats between and ; the busiest month was 2026-08 with 2 reports.

ATT&CK techniques observed

47 techniques observed across 4 of 4 tracked threats · Initial Access (7), Reconnaissance (6), Execution (5), Exfiltration (5), Collection (4), Resource Development (4)
  • T1005 Data from Local System — Collectionobserved in 4 of 4 tracked threats
  • T1052.001 Exfiltration Over Physical Medium: Exfiltration over USB — Exfiltrationobserved in 4 of 4 tracked threats
  • T1219 Remote Access Tools — Command and Controlobserved in 4 of 4 tracked threats
  • T1566.004 Spearphishing Voice — Initial Accessobserved in 4 of 4 tracked threats
  • T1567.002 Exfiltration to Cloud Storage — Exfiltrationobserved in 4 of 4 tracked threats
  • T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 3 of 4 tracked threats
  • T1039 Data from Network Shared Drive — Collectionobserved in 3 of 4 tracked threats
  • T1135 Network Share Discovery — Discoveryobserved in 3 of 4 tracked threats
  • T1204.002 User Execution: Malicious File — Executionobserved in 3 of 4 tracked threats
  • T1583.001 Domains — Resource Developmentobserved in 3 of 4 tracked threats
  • T1657 Financial Theft — Impactobserved in 3 of 4 tracked threats
  • T1021.001 Remote Desktop Protocol — Lateral Movementobserved in 2 of 4 tracked threats
  • T1048.002 Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Prot — Exfiltrationobserved in 2 of 4 tracked threats
  • T1059.001 PowerShell — Executionobserved in 2 of 4 tracked threats
  • T1059.003 Windows Command Shell — Executionobserved in 2 of 4 tracked threats

Tracked threats