# UNC3753

> As of 2026-06-07, UNC3753 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning campaign, ransomware. Also known as Luna Moth, Chatty Spider, SRG. ATT&CK coverage spans 40 techniques across 14 tactics in 2 of 2 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1039 (Data from Network Shared Drive), T1052.001 (Exfiltration Over Physical Medium: Exfiltration over USB).

- **Nation:** Russia
- **Tracked threats:** 2
- **Categories:** CAMPAIGN, RANSOMWARE
- **Also known as:** Luna Moth, Chatty Spider, SRG
- **As of:** 2026-06-07

## ATT&CK techniques observed

40 techniques observed across 2 of 2 tracked threats. Tactics: Initial Access (6), Collection (4), Execution (4), Exfiltration (4), Resource Development (4), Command and Control (3).

- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 2 of 2 tracked threats
- [T1039](https://intel.threadlinqs.com/technique/T1039) Data from Network Shared Drive — Collection — observed in 2 of 2 tracked threats
- [T1052.001](https://attack.mitre.org/techniques/T1052/001/) Exfiltration Over Physical Medium: Exfiltration over USB — Exfiltration — observed in 2 of 2 tracked threats
- [T1059.001](https://intel.threadlinqs.com/technique/T1059.001) PowerShell — Execution — observed in 2 of 2 tracked threats
- [T1083](https://intel.threadlinqs.com/technique/T1083) File and Directory Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1135](https://intel.threadlinqs.com/technique/T1135) Network Share Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1200](https://intel.threadlinqs.com/technique/T1200) Hardware Additions — Initial Access — observed in 2 of 2 tracked threats
- [T1204.002](https://intel.threadlinqs.com/technique/T1204.002) User Execution: Malicious File — Execution — observed in 2 of 2 tracked threats
- [T1219](https://intel.threadlinqs.com/technique/T1219) Remote Access Tools — Command and Control — observed in 2 of 2 tracked threats
- [T1566.004](https://intel.threadlinqs.com/technique/T1566.004) Spearphishing Voice — Initial Access — observed in 2 of 2 tracked threats
- [T1567.002](https://intel.threadlinqs.com/technique/T1567.002) Exfiltration to Cloud Storage — Exfiltration — observed in 2 of 2 tracked threats
- [T1583.001](https://intel.threadlinqs.com/technique/T1583.001) Domains — Resource Development — observed in 2 of 2 tracked threats
- [T1589](https://intel.threadlinqs.com/technique/T1589) Gather Victim Identity Information — Reconnaissance — observed in 2 of 2 tracked threats
- [T1657](https://intel.threadlinqs.com/technique/T1657) Financial Theft — Impact — observed in 2 of 2 tracked threats
- [T1021.001](https://intel.threadlinqs.com/technique/T1021.001) Remote Desktop Protocol — Lateral Movement — observed in 1 of 2 tracked threats

## Tracked threats

- [UNC3753 (Silent Ransom Group / Luna Moth) Escalation — Physical Office Intrusion & USB Data Exfiltration Against US Legal & Financial Services (FBI Flash CSA, 2026)](https://intel.threadlinqs.com/threat/TL-2026-0707) — HIGH
- [Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753) — IT Support Impersonation Campaign Targeting US Law Firms (FBI FLASH Advisory, May 2026)](https://intel.threadlinqs.com/threat/TL-2026-0612) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/UNC3753
