Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753) — IT Support Impersonation Campaign Targeting US Law Firms (FBI FLASH Advisory, May 2026) — Threadlinqs Intelligence
As of 2026-05-30, Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753) — IT Support Impersonation Campaign Targeting US Law Firms (FBI FLASH Advisory, May 2026) is a high-severity ransomware threat attributed to Silent Ransom Group, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-0612 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: Silent Ransom Group · FINANCIAL
The Silent Ransom Group (SRG) — also tracked as Luna Moth, Chatty Spider, and UNC3753 — has escalated a long-running data-theft extortion campaign against US-based law firms by impersonating internal
## Overview
Silent Ransom Group (SRG) is a financially motivated data-theft extortion crew that emerged in March 2022 as a splinter of the Conti ransomware syndicate, specifically the operators behind the BazarCall / BazarLoader callback-phishing program. Industry vendors have tracked the same actor under multiple names: Mandiant/Google as UNC3753, Microsoft as Storm-0257, CrowdStrike as Chatty Spider, and Sygnia/SentinelOne/others as Luna Moth. The FBI's May 2026 FLASH advisory consolidates the threat under the Silent Ransom Group label and warns that the cluster has materially escalated its operations against US law firms.
Unlike most ransomware brands, SRG does not deploy file-encryption malware. The group instead specializes in social engineering — primarily callback phishing (TOAD: Telephone-Oriented Attack Delivery) and live vishing — to obtain interactive sessions on victim endpoints using off-the-shelf, legitimate remote management software. Once present on a network, operators perform manual discovery, stage sensitive client matter files, and exfiltrate them to attacker-controlled cloud storage. Victims are then extorted under threat of publication on the actor's leak portal at business-data-leaks[.]com.
## Initial Access — Vishing and IT-Support Impersonation
The FBI advisory documents two dominant initial-access patterns for the 2025-2026 wave:
1. **Cold-call IT impersonation (vishing-first).** SRG operators directly phone employees of target law firms during US business hours, claiming to be a member of the firm's internal IT or managed-service-provider (MSP) help desk. The pretext is typically an "urgent overnight maintenance" or "security update" that requires the user to join a remote session. The operator walks the victim through downloading a legitimate RMM tool — most commonly Zoho Assist, Microsoft Quick Assist, AnyDesk, RustDesk, Syncro, Splashtop, or Atera — from the vendor's real distribution site, and enters a session/relay code that hands control to the attacker.
2. **Callback-phishing (BazarCall heritage).** SRG continues to operate Conti-era BazarCall-style email lures: low-volume, plain-text emails impersonating subscription confirmations or invoice receipts from brands such as Duolingo, Masterclass, Audible, or generic "premium support" services, with a US-based callback number. When the victim phones in to dispute the charge, the operator on the other end re-routes the conversation into the same IT-support pretext and remote-session installation flow.
In both flows the malware footprint at initial access is effectively zero — the binaries dropped are signed, vendor-issued RMM agents, which evades signature-based AV and most EDR allowlists.
## New 2026 Escalation — Physical IT-Technician Impersonation
The May 2026 FBI FLASH highlights a previously unobserved TTP: SRG-affiliated actors have, in at least a small number of confirmed incidents, physically visited victim law firm offices posing as third-party IT or printer-maintenance technicians. Once inside, the impostor attaches USB mass-storage or external SSD devices to a workstation or fileserver and copies data directly off-network, bypassing perimeter DLP. The FBI advises law firms to require government-issued ID verification and pre-arranged ticket numbers for any on-site IT visit, including those purporting to come from existing MSPs.
## Hands-on-Keyboard Tradecraft
After establishing the remote session, SRG operators move quickly (often within 1-3 hours) through a consistent post-access playbook:
- **Discovery.** Manual enumeration of mapped drives, document management systems (NetDocuments, iManage Work, Worldox), email archives, and accounting platforms (Elite 3E, Aderant). Operators target client matter folders, billing data, and partner-level mailboxes.
- **Tool staging.** Operators transfer additional binaries via the active RMM channel — typically `WinSCP.exe` (renamed) for SFTP exfiltration and `rclone.exe` (renamed, often m
Weaknesses (CWE)
CWE-1021, CWE-294, CWE-863
Target sectors: legal, professional-services, financial, healthcare, retail
Target regions: United States, Canada, United Kingdom, Australia
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1589, T1589.003, T1593, T1583.001, T1583.003, T1585.002, T1588.002, T1566.004, T1566.002, T1200