UNC3753 (Silent Ransom Group / Luna Moth) Escalation — Physical Office Intrusion & USB Data Exfiltration Against US Legal & Financial Services (FBI Flash CSA, 2026) — Threadlinqs Intelligence
As of 2026-06-07, UNC3753 (Silent Ransom Group / Luna Moth) Escalation — Physical Office Intrusion & USB Data Exfiltration Against US Legal & Financial Services (FBI Flash CSA, 2026) is a high-severity campaign threat attributed to UNC3753 (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-0707 · Severity: HIGH · Status: ACTIVE · Category: CAMPAIGN
Attribution: UNC3753 · Russia · FINANCIAL
Mandiant and the FBI attribute a financially-motivated data-theft extortion campaign (Jan-May 2026) to UNC3753 (aka Luna Moth, Chatty Spider, Silent Ransom Group) targeting US legal and financial
UNC3753 — tracked publicly as Silent Ransom Group (SRG), Luna Moth, and Chatty Spider — is a financially-motivated, Russia-linked extortion cluster active since at least March 2022 with tradecraft overlapping the UNC2686 BazarCall operations of 2021. Originally a ransomware affiliate deploying LOCKBIT.BLACK in 2022, the group pivoted to pure data-theft extortion and, in March 2025, shifted its lure from subscription/invoice billing themes to internal IT-helpdesk impersonation. Throughout the first half of 2026 the group has aggressively targeted US law firms and financial-services organizations, with public leaks affecting Orrick Herrington & Sutcliffe (January 2026), Jones Day, and Wood Smith Henning & Berman (Q1 2026), and a claimed breach of Ropers Majeski on 6 May 2026.
The campaign's defining 2026 escalation, the subject of an FBI TLP:CLEAR Flash advisory (26 May 2026) and a Google Cloud / Mandiant report (4 June 2026), is the addition of a PHYSICAL intrusion vector. When remote social engineering fails, SRG dispatches an operative in person to the victim's office. Posing as an IT technician performing a 'device imaging' or 'backup' in response to an earlier (benign) phishing email, the operative inserts an attacker-supplied USB drive or external hard disk directly into a victim workstation and copies privileged data offline — entirely bypassing network-based DLP and egress controls.
The remote kill chain remains active in parallel. Initial access begins with a deliberately benign invoice-themed email (no attachments or links) used to pretext a follow-up phone call (vishing). Actors impersonate internal IT/security staff, harvesting target personnel from public firm websites, and direct victims into Zoom, Microsoft Teams, Microsoft Terminal Services, or Quick Assist screen-sharing sessions. From there they install RMM tooling — AnyDesk, Bomgar, Zoho Assist, or SuperOps RMM — frequently delivered via Privnote self-destructing links and silent MSI installation (e.g. curl download piped to msiexec /quiet). Operators enumerate local directories, OneDrive, and mapped network shares, then perform keyword searches against iManage document-management repositories to locate tax records (W-2/W-9/1099), SSNs, audit files, and client legal agreements. Staged data is exfiltrated via WinSCP (portable), Rclone (hidden/renamed), FTP/SFTP, direct browser uploads to actor-controlled Google Drive accounts, or victim-initiated email forwarding to actor mailboxes. In one documented incident the actor moved 1.7 GB to Google Drive before pivoting to WinSCP to extract an additional 14.4 GB after Google disabled the account.
Extortion follows within ~30 minutes of the operator leaving the environment. Demands carry a strict three-day negotiation window and threaten employee/client notification, regulatory-fine and litigation pressure, and publication on the group's LEAKEDDATA / business-data-leaks[.]com data-leak site. The physical-intrusion TTP warrants detection logic — removable-media DLP, USB-write/insider endpoint monitoring, and front-desk technician verification — not covered by prior remote-callback threat tracking (related: TL-2026-0612).
Target sectors: legal, financial, professional services, accounting
Target regions: North America, United States
Detections & IOCs
As of 2026-07-20, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
CAMPAIGN, HIGH, threat intelligence, cybersecurity, T1589, T1583.001, T1566.004, T1566, T1200, T1133, T1204.002, T1059.001, T1059.003, T1569.002