UNC3753 (Silent Ransom Group / Luna Moth) Escalation — Physical Office Intrusion & USB Data Exfiltration Against US Legal & Financial Services (FBI Flash CSA, 2026)

UNC3753 (Silent Ransom Group / Luna Moth) Escalation (TL-2026-0707), also tracked as Luna Moth, is a high-severity campaign, first published 2026-06-07. It is attributed to UNC3753 (Russia) with medium confidence, affects US Legal Services Law Firms (iManage document repositories), maps to 22 MITRE ATT&CK techniques (T1005, T1021.001, T1021.004), and is covered by 9 detection rules and 21 indicators of compromise.

Key facts for TL-2026-0707

Threat ID
TL-2026-0707
Also known as
Luna Moth, Chatty Spider, Silent Ransom Group, Operation Silent Ransom
Severity
HIGH
Status
ACTIVE
Category
CAMPAIGN
First published
2026-06-07
Last reviewed
2026-06-07
Attribution
UNC3753
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
legal, financial, professional services, accounting
Target regions
North America, United States
Detection rules
9
Indicators of compromise
21

Malware and tooling in UNC3753 (Silent Ransom Group / Luna Moth) Escalation

Malware and tooling: AnyDesk, Bomgar, Rclone - S1040, SuperOps RMM, WinSCP, Zoho Assist

Mandiant and the FBI attribute a financially-motivated data-theft extortion campaign (Jan-May 2026) to UNC3753 (aka Luna Moth, Chatty Spider, Silent Ransom Group) targeting US legal and financial services. In a marked escalation from remote IT-support vishing, operatives now physically enter victim offices posing as IT technicians and exfiltrate privileged data to attacker-supplied USB/external drives. The full intrusion-to-extortion sequence frequently completes within a single business day, sometimes staging data in under an hour.

How UNC3753 (Silent Ransom Group / Luna Moth) Escalation works

UNC3753 — tracked publicly as Silent Ransom Group (SRG), Luna Moth, and Chatty Spider — is a financially-motivated, Russia-linked extortion cluster active since at least March 2022 with tradecraft overlapping the UNC2686 BazarCall operations of 2021. Originally a ransomware affiliate deploying LOCKBIT.BLACK in 2022, the group pivoted to pure data-theft extortion and, in March 2025, shifted its lure from subscription/invoice billing themes to internal IT-helpdesk impersonation. Throughout the first half of 2026 the group has aggressively targeted US law firms and financial-services organizations, with public leaks affecting Orrick Herrington & Sutcliffe (January 2026), Jones Day, and Wood Smith Henning & Berman (Q1 2026), and a claimed breach of Ropers Majeski on 6 May 2026.

The campaign's defining 2026 escalation, the subject of an FBI TLP:CLEAR Flash advisory (26 May 2026) and a Google Cloud / Mandiant report (4 June 2026), is the addition of a PHYSICAL intrusion vector. When remote social engineering fails, SRG dispatches an operative in person to the victim's office. Posing as an IT technician performing a 'device imaging' or 'backup' in response to an earlier (benign) phishing email, the operative inserts an attacker-supplied USB drive or external hard disk directly into a victim workstation and copies privileged data offline — entirely bypassing network-based DLP and egress controls.

The remote kill chain remains active in parallel. Initial access begins with a deliberately benign invoice-themed email (no attachments or links) used to pretext a follow-up phone call (vishing). Actors impersonate internal IT/security staff, harvesting target personnel from public firm websites, and direct victims into Zoom, Microsoft Teams, Microsoft Terminal Services, or Quick Assist screen-sharing sessions. From there they install RMM tooling — AnyDesk, Bomgar, Zoho Assist, or SuperOps RMM — frequently delivered via Privnote self-destructing links and silent MSI installation (e.g. curl download piped to msiexec /quiet). Operators enumerate local directories, OneDrive, and mapped network shares, then perform keyword searches against iManage document-management repositories to locate tax records (W-2/W-9/1099), SSNs, audit files, and client legal agreements. Staged data is exfiltrated via WinSCP (portable), Rclone (hidden/renamed), FTP/SFTP, direct browser uploads to actor-controlled Google Drive accounts, or victim-initiated email forwarding to actor mailboxes. In one documented incident the actor moved 1.7 GB to Google Drive before pivoting to WinSCP to extract an additional 14.4 GB after Google disabled the account.

Extortion follows within ~30 minutes of the operator leaving the environment. Demands carry a strict three-day negotiation window and threaten employee/client notification, regulatory-fine and litigation pressure, and publication on the group's LEAKEDDATA / business-data-leaks[.]com data-leak site. The physical-intrusion TTP warrants detection logic — removable-media DLP, USB-write/insider endpoint monitoring, and front-desk technician verification — not covered by prior remote-callback threat tracking (related: TL-2026-0612).

MITRE ATT&CK techniques used in TL-2026-0707

Collection

T1005 Data from Local System; T1039 Data from Network Shared Drive; T1530 Data from Cloud Storage

Lateral Movement

T1021.001 Remote Services: Remote Desktop Protocol; T1021.004 Remote Services: SSH

Exfiltration

T1048 Exfiltration Over Alternative Protocol; T1052.001 Exfiltration Over Physical Medium: Exfiltration over USB; T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1204.002 User Execution: Malicious File; T1569.002 System Services: Service Execution

Discovery

T1083 File and Directory Discovery; T1135 Network Share Discovery

Initial Access

T1133 External Remote Services; T1200 Hardware Additions; T1566 Phishing; T1566.004 Phishing: Spearphishing Voice

Command and Control

T1219 Remote Access Tools

Resource Development

T1583.001 Acquire Infrastructure: Domains

Reconnaissance

T1589 Gather Victim Identity Information

Impact

T1657 Financial Theft

Affected products and versions in UNC3753 (Silent Ransom Group / Luna Moth) Escalation

  • US Legal Services — Law Firms (iManage document repositories)
    Vulnerable versions: all
  • US Financial Services — Accounting / Financial Advisory Firms
    Vulnerable versions: all

Remediation for UNC3753 (Silent Ransom Group / Luna Moth) Escalation

Immediate actions

  • Enforce out-of-band identity verification for any on-site or remote IT technician before granting workstation access; require pre-scheduled work orders and photo-ID logging by front-desk staff
  • Disable USB mass-storage read/write via GPO/MDM and block removable-media device installation on endpoints holding privileged data
  • Block installation and execution of unsanctioned RMM tools (AnyDesk, Bomgar, Zoho Assist, SuperOps) via application control (WDAC/EDR)
  • Block the known C2/exfil IPs and typosquat helpdesk domains at the perimeter; alert on connections to privnote.com and business-data-leaks.com

Workarounds

  • Restrict interactive screen-control features in Microsoft Teams, Zoom, and Quick Assist
  • Monitor outbound SSH/port-22 and FTP for high-volume WinSCP/Rclone transfers with byte-count session logging

Longer-term hardening

  • Deploy removable-media DLP with content inspection and USB-write alerting
  • Restrict VDI/VPN authentication to corporate-owned, compliant devices with MFA step-up; block BYOD pivots into corporate VDI
  • Implement iManage/SharePoint anomaly alerting for rapid keyword searches and mass downloads, with MFA on document repositories
  • Mandatory escort policy for all technical/visitor personnel; conduct vishing-focused security awareness training

Timeline of UNC3753 (Silent Ransom Group / Luna Moth) Escalation

  • UNC3753 (Luna Moth / Silent Ransom Group) first observed; tradecraft overlaps UNC2686 BazarCall operations (2021).
  • Group operated as a ransomware affiliate deploying LOCKBIT.BLACK before pivoting to data-theft-only extortion.
  • Sustained targeting of US legal and financial-services organizations begins.
  • Actors shift lures from subscription/invoice billing themes to internal IT-helpdesk impersonation.
  • Data from Orrick, Herrington & Sutcliffe posted publicly after the firm declined the ransom demand.
  • Jones Day and Wood Smith Henning & Berman suffer data exposures during Q1 2026.
  • SRG claims responsibility for a breach at Ropers Majeski.
  • FBI issues TLP:CLEAR Flash advisory (260526) warning of SRG IT-personnel impersonation and in-person data theft.
  • Public reporting confirms physical office intrusion with USB data theft; ~38 firms already leaked.
  • Google Cloud / Mandiant publishes detailed UNC3753 technical analysis including tools, IOCs, and MITRE mappings.
  • Threadlinqs Intelligence documents the escalation as TL-2026-0707 with removable-media detection focus.

Sources cited for UNC3753 (Silent Ransom Group / Luna Moth) Escalation

Threats related to UNC3753 (Silent Ransom Group / Luna Moth) Escalation

Detection coverage for TL-2026-0707

As of 2026-06-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0707 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats