UNC3753 (Silent Ransom Group / Luna Moth) Escalation — Physical Office Intrusion & USB Data Exfiltration Against US Legal & Financial Services (FBI Flash CSA, 2026)
UNC3753 (Silent Ransom Group / Luna Moth) Escalation (TL-2026-0707), also tracked as Luna Moth, is a high-severity campaign, first published 2026-06-07. It is attributed to UNC3753 (Russia) with medium confidence, affects US Legal Services Law Firms (iManage document repositories), maps to 22 MITRE ATT&CK techniques (T1005, T1021.001, T1021.004), and is covered by 9 detection rules and 21 indicators of compromise.
Key facts for TL-2026-0707
- Threat ID
- TL-2026-0707
- Also known as
- Luna Moth, Chatty Spider, Silent Ransom Group, Operation Silent Ransom
- Severity
- HIGH
- Status
- ACTIVE
- Category
- CAMPAIGN
- First published
- 2026-06-07
- Last reviewed
- 2026-06-07
- Attribution
- UNC3753
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- legal, financial, professional services, accounting
- Target regions
- North America, United States
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in UNC3753 (Silent Ransom Group / Luna Moth) Escalation
Malware and tooling: AnyDesk, Bomgar, Rclone - S1040, SuperOps RMM, WinSCP, Zoho Assist
Mandiant and the FBI attribute a financially-motivated data-theft extortion campaign (Jan-May 2026) to UNC3753 (aka Luna Moth, Chatty Spider, Silent Ransom Group) targeting US legal and financial services. In a marked escalation from remote IT-support vishing, operatives now physically enter victim offices posing as IT technicians and exfiltrate privileged data to attacker-supplied USB/external drives. The full intrusion-to-extortion sequence frequently completes within a single business day, sometimes staging data in under an hour.
How UNC3753 (Silent Ransom Group / Luna Moth) Escalation works
UNC3753 — tracked publicly as Silent Ransom Group (SRG), Luna Moth, and Chatty Spider — is a financially-motivated, Russia-linked extortion cluster active since at least March 2022 with tradecraft overlapping the UNC2686 BazarCall operations of 2021. Originally a ransomware affiliate deploying LOCKBIT.BLACK in 2022, the group pivoted to pure data-theft extortion and, in March 2025, shifted its lure from subscription/invoice billing themes to internal IT-helpdesk impersonation. Throughout the first half of 2026 the group has aggressively targeted US law firms and financial-services organizations, with public leaks affecting Orrick Herrington & Sutcliffe (January 2026), Jones Day, and Wood Smith Henning & Berman (Q1 2026), and a claimed breach of Ropers Majeski on 6 May 2026.
The campaign's defining 2026 escalation, the subject of an FBI TLP:CLEAR Flash advisory (26 May 2026) and a Google Cloud / Mandiant report (4 June 2026), is the addition of a PHYSICAL intrusion vector. When remote social engineering fails, SRG dispatches an operative in person to the victim's office. Posing as an IT technician performing a 'device imaging' or 'backup' in response to an earlier (benign) phishing email, the operative inserts an attacker-supplied USB drive or external hard disk directly into a victim workstation and copies privileged data offline — entirely bypassing network-based DLP and egress controls.
The remote kill chain remains active in parallel. Initial access begins with a deliberately benign invoice-themed email (no attachments or links) used to pretext a follow-up phone call (vishing). Actors impersonate internal IT/security staff, harvesting target personnel from public firm websites, and direct victims into Zoom, Microsoft Teams, Microsoft Terminal Services, or Quick Assist screen-sharing sessions. From there they install RMM tooling — AnyDesk, Bomgar, Zoho Assist, or SuperOps RMM — frequently delivered via Privnote self-destructing links and silent MSI installation (e.g. curl download piped to msiexec /quiet). Operators enumerate local directories, OneDrive, and mapped network shares, then perform keyword searches against iManage document-management repositories to locate tax records (W-2/W-9/1099), SSNs, audit files, and client legal agreements. Staged data is exfiltrated via WinSCP (portable), Rclone (hidden/renamed), FTP/SFTP, direct browser uploads to actor-controlled Google Drive accounts, or victim-initiated email forwarding to actor mailboxes. In one documented incident the actor moved 1.7 GB to Google Drive before pivoting to WinSCP to extract an additional 14.4 GB after Google disabled the account.
Extortion follows within ~30 minutes of the operator leaving the environment. Demands carry a strict three-day negotiation window and threaten employee/client notification, regulatory-fine and litigation pressure, and publication on the group's LEAKEDDATA / business-data-leaks[.]com data-leak site. The physical-intrusion TTP warrants detection logic — removable-media DLP, USB-write/insider endpoint monitoring, and front-desk technician verification — not covered by prior remote-callback threat tracking (related: TL-2026-0612).
MITRE ATT&CK techniques used in TL-2026-0707
Collection
T1005 Data from Local System; T1039 Data from Network Shared Drive; T1530 Data from Cloud Storage
Lateral Movement
T1021.001 Remote Services: Remote Desktop Protocol; T1021.004 Remote Services: SSH
Exfiltration
T1048 Exfiltration Over Alternative Protocol; T1052.001 Exfiltration Over Physical Medium: Exfiltration over USB; T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1204.002 User Execution: Malicious File; T1569.002 System Services: Service Execution
Discovery
T1083 File and Directory Discovery; T1135 Network Share Discovery
Initial Access
T1133 External Remote Services; T1200 Hardware Additions; T1566 Phishing; T1566.004 Phishing: Spearphishing Voice
Command and Control
Resource Development
T1583.001 Acquire Infrastructure: Domains
Reconnaissance
T1589 Gather Victim Identity Information
Impact
Affected products and versions in UNC3753 (Silent Ransom Group / Luna Moth) Escalation
- US Legal Services — Law Firms (iManage document repositories)
Vulnerable versions: all - US Financial Services — Accounting / Financial Advisory Firms
Vulnerable versions: all
Remediation for UNC3753 (Silent Ransom Group / Luna Moth) Escalation
Immediate actions
- Enforce out-of-band identity verification for any on-site or remote IT technician before granting workstation access; require pre-scheduled work orders and photo-ID logging by front-desk staff
- Disable USB mass-storage read/write via GPO/MDM and block removable-media device installation on endpoints holding privileged data
- Block installation and execution of unsanctioned RMM tools (AnyDesk, Bomgar, Zoho Assist, SuperOps) via application control (WDAC/EDR)
- Block the known C2/exfil IPs and typosquat helpdesk domains at the perimeter; alert on connections to privnote.com and business-data-leaks.com
Workarounds
- Restrict interactive screen-control features in Microsoft Teams, Zoom, and Quick Assist
- Monitor outbound SSH/port-22 and FTP for high-volume WinSCP/Rclone transfers with byte-count session logging
Longer-term hardening
- Deploy removable-media DLP with content inspection and USB-write alerting
- Restrict VDI/VPN authentication to corporate-owned, compliant devices with MFA step-up; block BYOD pivots into corporate VDI
- Implement iManage/SharePoint anomaly alerting for rapid keyword searches and mass downloads, with MFA on document repositories
- Mandatory escort policy for all technical/visitor personnel; conduct vishing-focused security awareness training
Timeline of UNC3753 (Silent Ransom Group / Luna Moth) Escalation
- UNC3753 (Luna Moth / Silent Ransom Group) first observed; tradecraft overlaps UNC2686 BazarCall operations (2021).
- Group operated as a ransomware affiliate deploying LOCKBIT.BLACK before pivoting to data-theft-only extortion.
- Sustained targeting of US legal and financial-services organizations begins.
- Actors shift lures from subscription/invoice billing themes to internal IT-helpdesk impersonation.
- Data from Orrick, Herrington & Sutcliffe posted publicly after the firm declined the ransom demand.
- Jones Day and Wood Smith Henning & Berman suffer data exposures during Q1 2026.
- SRG claims responsibility for a breach at Ropers Majeski.
- FBI issues TLP:CLEAR Flash advisory (260526) warning of SRG IT-personnel impersonation and in-person data theft.
- Public reporting confirms physical office intrusion with USB data theft; ~38 firms already leaked.
- Google Cloud / Mandiant publishes detailed UNC3753 technical analysis including tools, IOCs, and MITRE mappings.
- Threadlinqs Intelligence documents the escalation as TL-2026-0707 with removable-media detection focus.
Sources cited for UNC3753 (Silent Ransom Group / Luna Moth) Escalation
- Ongoing Targeted Campaign Against US Law Firms (UNC3753)
- FBI Flash: Silent Ransom Group Impersonating IT Personnel through Social Engineering
- FBI warns of Silent Ransom Group in-person data theft attacks
- UNC3753 Targets US Law Firms with Vishing, RMM Tools, and Physical Break-Ins
- Silent Ransom Group Sends Operatives Into Law Firm Offices: 38 Firms Already Leaked
- FBI Flash Report TLP:Clear: Silent Ransom Group Impersonating IT Personnel (AHA)
Threats related to UNC3753 (Silent Ransom Group / Luna Moth) Escalation
- UNC3753 (Luna Moth / Silent Ransom Group) Vishing and Physical Intrusion Campaign Against US Law Firms
- Troutman Pepper Locke LLP Data Theft Extortion by SilentRansomGroup (Repeat Attack Including Physical Intrusion)
- Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753) — IT Support Impersonation Campaign Targeting US Law Firms (FBI FLASH Advisory, May 2026)
- Silent Ransom Group (Luna Moth) Targets US Law Firms via IT Support Impersonation and Physical Intrusion
Detection coverage for TL-2026-0707
As of 2026-06-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0707 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.