Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753) — IT Support Impersonation Campaign Targeting US Law Firms (FBI FLASH Advisory, May 2026)
Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753) (TL-2026-0612), also tracked as Luna Moth, is a high-severity ransomware operation, first published 2026-05-28. It is attributed to Silent Ransom Group with high confidence, affects Zoho Zoho Assist, maps to 32 MITRE ATT&CK techniques (T1005, T1021.002, T1036.003), and is covered by 9 detection rules and 30 indicators of compromise.
Key facts for TL-2026-0612
- Threat ID
- TL-2026-0612
- Also known as
- Luna Moth, Chatty Spider, UNC3753, Storm-0257, Silent Ransom
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-05-28
- Last reviewed
- 2026-05-28
- Attribution
- Silent Ransom Group
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- legal, professional-services, financial, healthcare, retail
- Target regions
- United States, Canada, United Kingdom, Australia
- Detection rules
- 9
- Indicators of compromise
- 30
Malware and tooling in Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753)
Malware and tooling: AnyDesk, Atera, Microsoft Quick Assist, Rclone - S1040, RustDesk, Splashtop Streamer, Syncro, WinSCP, Zoho Assist
The Silent Ransom Group (SRG) — also tracked as Luna Moth, Chatty Spider, and UNC3753 — has escalated a long-running data-theft extortion campaign against US-based law firms by impersonating internal IT support over the phone (vishing) and email to coerce victims into installing legitimate remote management tools (Zoho Assist, Quick Assist, AnyDesk, RustDesk, Syncro, Splashtop, Atera). After hands-on-keyboard access, operators exfiltrate sensitive client matter data with WinSCP and a hidden Rclone binary to attacker-controlled OneDrive/Google Drive tenants, then extort victims under threat of publication on business-data-leaks[.]com. The FBI's May 2026 FLASH advisory also documents a new, more aggressive TTP in which SRG affiliates physically appear at firm offices posing as IT technicians to attach external/USB media for in-person exfiltration. The group does not deploy ransomware encryption — extortion is purely leverage-based on stolen data.
How Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753) works
## Overview
Silent Ransom Group (SRG) is a financially motivated data-theft extortion crew that emerged in March 2022 as a splinter of the Conti ransomware syndicate, specifically the operators behind the BazarCall / BazarLoader callback-phishing program. Industry vendors have tracked the same actor under multiple names: Mandiant/Google as UNC3753, Microsoft as Storm-0257, CrowdStrike as Chatty Spider, and Sygnia/SentinelOne/others as Luna Moth. The FBI's May 2026 FLASH advisory consolidates the threat under the Silent Ransom Group label and warns that the cluster has materially escalated its operations against US law firms.
Unlike most ransomware brands, SRG does not deploy file-encryption malware. The group instead specializes in social engineering — primarily callback phishing (TOAD: Telephone-Oriented Attack Delivery) and live vishing — to obtain interactive sessions on victim endpoints using off-the-shelf, legitimate remote management software. Once present on a network, operators perform manual discovery, stage sensitive client matter files, and exfiltrate them to attacker-controlled cloud storage. Victims are then extorted under threat of publication on the actor's leak portal at business-data-leaks[.]com.
## Initial Access — Vishing and IT-Support Impersonation
The FBI advisory documents two dominant initial-access patterns for the 2025-2026 wave:
1. **Cold-call IT impersonation (vishing-first).** SRG operators directly phone employees of target law firms during US business hours, claiming to be a member of the firm's internal IT or managed-service-provider (MSP) help desk. The pretext is typically an "urgent overnight maintenance" or "security update" that requires the user to join a remote session. The operator walks the victim through downloading a legitimate RMM tool — most commonly Zoho Assist, Microsoft Quick Assist, AnyDesk, RustDesk, Syncro, Splashtop, or Atera — from the vendor's real distribution site, and enters a session/relay code that hands control to the attacker.
2. **Callback-phishing (BazarCall heritage).** SRG continues to operate Conti-era BazarCall-style email lures: low-volume, plain-text emails impersonating subscription confirmations or invoice receipts from brands such as Duolingo, Masterclass, Audible, or generic "premium support" services, with a US-based callback number. When the victim phones in to dispute the charge, the operator on the other end re-routes the conversation into the same IT-support pretext and remote-session installation flow.
In both flows the malware footprint at initial access is effectively zero — the binaries dropped are signed, vendor-issued RMM agents, which evades signature-based AV and most EDR allowlists.
## New 2026 Escalation — Physical IT-Technician Impersonation
The May 2026 FBI FLASH highlights a previously unobserved TTP: SRG-affiliated actors have, in at least a small number of confirmed incidents, physically visited victim law firm offices posing as third-party IT or printer-maintenance technicians. Once inside, the impostor attaches USB mass-storage or external SSD devices to a workstation or fileserver and copies data directly off-network, bypassing perimeter DLP. The FBI advises law firms to require government-issued ID verification and pre-arranged ticket numbers for any on-site IT visit, including those purporting to come from existing MSPs.
## Hands-on-Keyboard Tradecraft
After establishing the remote session, SRG operators move quickly (often within 1-3 hours) through a consistent post-access playbook:
- **Discovery.** Manual enumeration of mapped drives, document management systems (NetDocuments, iManage Work, Worldox), email archives, and accounting platforms (Elite 3E, Aderant). Operators target client matter folders, billing data, and partner-level mailboxes. - **Tool staging.** Operators transfer additional binaries via the active RMM channel — typically `WinSCP.exe` (renamed) for SFTP exfiltration and `rclone.exe` (renamed, often masquerading as `svchost.exe`, `chrome.exe`, or `OneDriveStandaloneUpdater.exe`) for cloud exfil. PowerShell is used sparingly to avoid Script Block Logging. - **Exfiltration.** Rclone is configured with attacker-controlled OneDrive or Google Drive remotes. WinSCP is used for direct SFTP to actor VPS infrastructure (frequently on M247, BL Networks, FlokiNET, and Stark Industries Solutions ASNs). Transfers are large but throttled to blend with normal cloud-sync baselines. - **No encryption, no destruction.** SRG explicitly avoids ransomware deployment; the leverage is exclusively the stolen data and the leak-site threat. There is no observed wiper or destructive activity.
## Extortion and Leak Site
Victims receive an extortion email from a ProtonMail or Tutanota address within 24-72 hours of exfiltration, with a sample directory listing of the stolen data. Demands in 2025-2026 have ranged from $250,000 to $5,000,000 USD, payable in Bitcoin. Non-paying victims are listed on business-data-leaks[.]com, an actor-operated Tor-mirrored clearweb leak site that has been continuously operational since mid-2023.
## Why Law Firms
Law firms hold uniquely high-leverage data: privileged attorney-client communications, M&A diligence files, sealed litigation records, regulatory investigation materials, and high-net-worth client PII. Reputational damage from a publication is severe and bar-association disclosure obligations create regulatory pressure. SRG explicitly cites these factors in its extortion correspondence.
## Attribution Confidence
MITRE, Mandiant, Microsoft, CrowdStrike, and the FBI independently converge on the Conti-splinter origin and on the identity of the operator cluster across the Luna Moth / Chatty Spider / UNC3753 / Silent Ransom Group labels. Attribution to a specific nation-state is not asserted; SRG is assessed as Russian-speaking, financially motivated, and non-state-aligned.
MITRE ATT&CK techniques used in TL-2026-0612
Collection
T1005 Data from Local System; T1039 Data from Network Shared Drive; T1560 Archive Collected Data
Lateral Movement
T1021.002 Remote Services: SMB/Windows Admin Shares
Defense Evasion
T1036.003 Rename Legitimate Utilities; T1036.005 Match Legitimate Resource Name or Location
Exfiltration
T1048.002 Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol; T1052.001 Exfiltration Over Physical Medium: Exfiltration over USB; T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1204.002 User Execution: Malicious File
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1105 Ingress Tool Transfer; T1219 Remote Access Tools
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery; T1135 Network Share Discovery
Initial Access
T1091 Replication Through Removable Media; T1200 Hardware Additions; T1566.002 Phishing: Spearphishing Link; T1566.004 Phishing: Spearphishing Voice
Persistence
T1543.003 Create or Modify System Process: Windows Service
Credential Access
T1555.003 Credentials from Password Stores: Credentials from Web Browsers
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1583.003 Acquire Infrastructure: Virtual Private Server; T1585.002 Establish Accounts: Email Accounts; T1588.002 Obtain Capabilities: Tool
Reconnaissance
T1589 Gather Victim Identity Information; T1589.003 Gather Victim Identity Information: Employee Names; T1593 Search Open Websites/Domains
Impact
defense-impairment
Affected products and versions in Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753)
- Zoho — Zoho Assist
Vulnerable versions: all (abused as living-off-the-land) - Microsoft — Quick Assist
Vulnerable versions: all (abused as living-off-the-land) - AnyDesk Software — AnyDesk
Vulnerable versions: all (abused as living-off-the-land) - RustDesk — RustDesk
Vulnerable versions: all (abused as living-off-the-land) - Servably (Syncro) — Syncro RMM
Vulnerable versions: all (abused as living-off-the-land) - Splashtop — Splashtop Streamer
Vulnerable versions: all (abused as living-off-the-land) - Atera Networks — Atera RMM
Vulnerable versions: all (abused as living-off-the-land)
Remediation for Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753)
Immediate actions
- Block business-data-leaks[.]com and known SRG exfil infrastructure at egress proxy/DNS
- Audit all installed RMM/remote-support tools (Zoho Assist, Quick Assist, AnyDesk, RustDesk, Syncro, Splashtop, Atera, ScreenConnect) and remove any not sanctioned by IT
- Disable Microsoft Quick Assist via GPO or AppLocker where business need is not justified
- Block download/execution of rclone.exe and WinSCP.exe outside of approved admin workstations
- Brief all reception, executive assistant, and partner administrative staff on physical IT-impersonation TTP — require pre-arranged ticket number and government ID for any on-site IT visit
- Configure DLP / CASB to alert on large outbound transfers to personal/unmanaged OneDrive and Google Drive tenants
- Hunt for rename-masquerade Rclone binaries (chrome.exe, svchost.exe, OneDriveStandaloneUpdater.exe in non-standard paths)
Workarounds
- Where Quick Assist must remain available, restrict it via Intune / GPO to inbound sessions initiated by helpdesk staff only
- Force RMM vendor connections through corporate VPN and block direct WAN access to vendor relay servers
Longer-term hardening
- Deploy application allowlisting (Windows Defender Application Control or AppLocker) to restrict RMM tool execution to authorized binaries and paths
- Implement Conditional Access policies blocking cloud-sync of corporate data to unmanaged Microsoft and Google tenants
- Mandate phishing-resistant MFA (FIDO2/WebAuthn) on all attorney and staff accounts including document management systems
- Run quarterly callback-phishing and vishing tabletop exercises tailored to legal-sector pretexts
- Deploy EDR with behavioral detection tuned for RMM-tool abuse and outbound cloud-storage exfiltration patterns
- Establish a verified internal IT callback number and publish it on intranet, partner directory, and physical badge backs
Weaknesses (CWE) in Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753)
CWE-1021, CWE-294, CWE-863
Timeline of Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753)
- Silent Ransom Group splinters from Conti syndicate after Conti shutdown, retaining BazarCall callback-phishing tradecraft.
- Sygnia publishes initial Luna Moth profile describing fake-subscription callback phishing targeting legal and retail sectors.
- Industry analysis (Rapid7) documents SRG's adoption of rename-masqueraded Rclone for cloud exfiltration to OneDrive and Google Drive.
- business-data-leaks[.]com goes operational as SRG's dedicated extortion publication portal.
- FBI issues Private Industry Notification on Silent Ransom Group callback phishing targeting US-based organizations.
- Mandiant (Google Cloud) formalizes UNC3753 attribution and links Luna Moth, Chatty Spider, and Silent Ransom Group to the same operator cluster.
- Microsoft publishes Storm-0257 actor profile, documenting Quick Assist abuse as a primary initial-access vector.
- CISA joint #StopRansomware advisory highlights encryption-less data-extortion model exemplified by SRG.
- Sygnia and ABA Cybersecurity Task Force report sharp uptick in SRG incidents at AmLaw 200 firms during Q3-Q4 2025.
- First confirmed in-person IT-technician impersonation incident at a Midwestern US law firm; USB exfiltration of matter files.
- FBI FLASH advisory consolidates 2025-2026 SRG activity against US law firms, formally documenting physical-impersonation TTP and updated RMM tool list.
- As of 2026-05-29, Silent Ransom Group (Luna Moth/UNC3753) is firmly active: FBI issued a FLASH advisory on May 26, 2026 warning of escalating in-person IT-impersonation/USB exfil against US law firms. 100+ attacks claimed, 38+ firms leaked on the live business-data-leaks site (Orrick, Jones Day, Ropers Majeski May 6); no arrests or takedown.
Sources cited for Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753)
- Silent Ransom Group Targets Law Firms With IT Support Impersonation Attacks
- FBI FLASH: Silent Ransom Group Continues Targeting US Law Firms (CU-000XXX-MW)
- FBI PIN — Silent Ransom Group Callback Phishing (March 2024)
- Mandiant — UNC3753: From BazarCall to Callback Phishing Extortion
- Sygnia — Luna Moth Callback Phishing Campaigns Targeting Legal and Retail Sectors
- Microsoft Security — Storm-0257 Activity Profile
- CISA #StopRansomware Joint Advisory — Data Extortion Without Encryption
- Rapid7 — Detecting Rclone Abuse in Enterprise Exfiltration
- Huntress — Quick Assist Abuse by Social-Engineering Threat Actors
- ABA Cybersecurity Legal Task Force — Law Firm Data Extortion Trends
Threats related to Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753)
- Silent Ransom Group (Luna Moth) Targets US Law Firms via IT Support Impersonation and Physical Intrusion
- Troutman Pepper Locke LLP Data Theft Extortion by SilentRansomGroup (Repeat Attack Including Physical Intrusion)
- UNC3753 (Silent Ransom Group / Luna Moth) Escalation — Physical Office Intrusion & USB Data Exfiltration Against US Legal & Financial Services (FBI Flash CSA, 2026)
- UNC3753 (Luna Moth / Silent Ransom Group) Vishing and Physical Intrusion Campaign Against US Law Firms
Detection coverage for TL-2026-0612
As of 2026-05-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0612 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.