Activity timeline
UNC3753 appears in 2 tracked threats between and ; the busiest month was 2026-05 with 1 report.
ATT&CK techniques observed
- T1005 Data from Local System — Collectionobserved in 2 of 2 tracked threats
- T1039 Data from Network Shared Drive — Collectionobserved in 2 of 2 tracked threats
- T1052.001 Exfiltration Over Physical Medium: Exfiltration over USB — Exfiltrationobserved in 2 of 2 tracked threats
- T1059.001 PowerShell — Executionobserved in 2 of 2 tracked threats
- T1083 File and Directory Discovery — Discoveryobserved in 2 of 2 tracked threats
- T1135 Network Share Discovery — Discoveryobserved in 2 of 2 tracked threats
- T1200 Hardware Additions — Initial Accessobserved in 2 of 2 tracked threats
- T1204.002 User Execution: Malicious File — Executionobserved in 2 of 2 tracked threats
- T1219 Remote Access Tools — Command and Controlobserved in 2 of 2 tracked threats
- T1566.004 Spearphishing Voice — Initial Accessobserved in 2 of 2 tracked threats
- T1567.002 Exfiltration to Cloud Storage — Exfiltrationobserved in 2 of 2 tracked threats
- T1583.001 Domains — Resource Developmentobserved in 2 of 2 tracked threats
- T1589 Gather Victim Identity Information — Reconnaissanceobserved in 2 of 2 tracked threats
- T1657 Financial Theft — Impactobserved in 2 of 2 tracked threats
- T1021.001 Remote Desktop Protocol — Lateral Movementobserved in 1 of 2 tracked threats
Tracked threats
- UNC3753 (Silent Ransom Group / Luna Moth) Escalation — Physical Office Intrusion & USB Data Exfiltration Against US Legal & Financial Services (FBI Flash CSA, 2026)HIGH
- Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753) — IT Support Impersonation Campaign Targeting US Law Firms (FBI FLASH Advisory, May 2026)HIGH