Threadlinqs IntelligenceStart free

Threat actorRussiaTracked since 2026-05

UNC3753

Also known as:Luna MothChatty SpiderSRG

As of 2026-06-07, UNC3753 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning campaign, ransomware. Also known as Luna Moth, Chatty Spider, SRG. ATT&CK coverage spans 40 techniques across 14 tactics in 2 of 2 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1039 (Data from Network Shared Drive), T1052.001 (Exfiltration Over Physical Medium: Exfiltration over USB).

Tracked threats
22 high
First seen
2026-05-28
Last seen
2026-06-07
ATT&CK techniques
40across 2 of 2 threats
Related CVEs
0None referenced
Attribution
RussiaNation or origin
Nation: Russia · 2 tracked threat(s) · Categories: CAMPAIGN, RANSOMWARE

Activity timeline

UNC3753 appears in 2 tracked threats between and ; the busiest month was 2026-05 with 1 report.

ATT&CK techniques observed

40 techniques observed across 2 of 2 tracked threats · Initial Access (6), Collection (4), Execution (4), Exfiltration (4), Resource Development (4), Command and Control (3)
  • T1005 Data from Local System — Collectionobserved in 2 of 2 tracked threats
  • T1039 Data from Network Shared Drive — Collectionobserved in 2 of 2 tracked threats
  • T1052.001 Exfiltration Over Physical Medium: Exfiltration over USB — Exfiltrationobserved in 2 of 2 tracked threats
  • T1059.001 PowerShell — Executionobserved in 2 of 2 tracked threats
  • T1083 File and Directory Discovery — Discoveryobserved in 2 of 2 tracked threats
  • T1135 Network Share Discovery — Discoveryobserved in 2 of 2 tracked threats
  • T1200 Hardware Additions — Initial Accessobserved in 2 of 2 tracked threats
  • T1204.002 User Execution: Malicious File — Executionobserved in 2 of 2 tracked threats
  • T1219 Remote Access Tools — Command and Controlobserved in 2 of 2 tracked threats
  • T1566.004 Spearphishing Voice — Initial Accessobserved in 2 of 2 tracked threats
  • T1567.002 Exfiltration to Cloud Storage — Exfiltrationobserved in 2 of 2 tracked threats
  • T1583.001 Domains — Resource Developmentobserved in 2 of 2 tracked threats
  • T1589 Gather Victim Identity Information — Reconnaissanceobserved in 2 of 2 tracked threats
  • T1657 Financial Theft — Impactobserved in 2 of 2 tracked threats
  • T1021.001 Remote Desktop Protocol — Lateral Movementobserved in 1 of 2 tracked threats

Tracked threats