Troutman Pepper Locke LLP Data Theft Extortion by SilentRansomGroup (Repeat Attack Including Physical Intrusion) — Threadlinqs Intelligence
As of 2026-08-21, Troutman Pepper Locke LLP Data Theft Extortion by SilentRansomGroup (Repeat Attack Including Physical Intrusion) is a high-severity ransomware threat attributed to SilentRansomGroup (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 22 indicators of compromise.
Threat ID: TL-2026-2103 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: SilentRansomGroup · Russia · FINANCIAL
SilentRansomGroup (UNC3753/Luna Moth/Chatty Spider) added Am Law 50 firm Troutman Pepper Locke to its LEAKEDDATA leak site on August 18, 2026, claiming this is the second time they have breached the
On August 18, 2026, the threat intelligence team at ThreatMon detected and reported that SilentRansomGroup (also tracked as UNC3753, Luna Moth, Chatty Spider, and LeakedData) listed Troutman Pepper Locke LLP as a victim on its dark web LEAKEDDATA leak site at business-data-leaks[.]com. The group posted a statement declaring this was the "2nd time we attacked them in a year (first time through physical intrusion), will continue our attacks." The claim indicates a persistent, targeted campaign against one of the largest law firms in the United States.
SilentRansomGroup is a financially motivated cyber extortion group active since at least March 2022, originating from the Ryuk/Conti ransomware syndicate. The group initially deployed LOCKBIT.BLACK ransomware but pivoted by 2025 to pure data-theft extortion — stealing sensitive data and threatening its publication rather than deploying encryption. The group has been the subject of a May 2025 FBI Cyber Flash Alert, a January-May 2026 Mandiant campaign analysis, and a June 2026 Cloud Security Alliance research note, all documenting their novel hybrid approach combining remote social engineering with in-person physical office intrusions.
The group's standard attack chain unfolds within a single business day, often in under one hour. Attackers first send benign invoice-themed phishing emails from consumer email accounts with no malicious links or attachments, establishing a pretext for follow-up phone calls. In the second stage, they impersonate the target organization's internal IT helpdesk or security team via direct phone calls (vishing), fabricating urgency around security issues or data migrations. They direct the target to join a screen-sharing session via Microsoft Teams, Zoom, Quick Assist, or Windows Terminal Services, then convince them to install legitimate Remote Monitoring and Management (RMM) tools such as AnyDesk, Zoho Assist, Bomgar, SuperOps, Splashtop, or Atera. Installation commands are transmitted via privnote[.]com self-destructing messages to eliminate forensic artifacts.
Once remote access is achieved, the attackers pivot to corporate VDI environments from compromised BYOD endpoints, using Windows 365 or Citrix clients. They conduct system enumeration, crawl mapped network drives, and specifically target document management platforms such as iManage using keyword searches for tax records (W-2, W-9, 1099), audit files, corporate client agreements, and Social Security numbers. Staged data is compiled in the user's Downloads folder or Roaming profile path, then exfiltrated via WinSCP, Rclone (often renamed), or browser-based drag-and-drop uploads to actor-controlled Google Drive and OneDrive accounts. In one documented Mandiant case, 1.7 GB was exfiltrated from OneDrive to Google Drive followed by an additional 14.4 GB via WinSCP from a VDI session.
Extortion demands arrive within 30 minutes of the attackers exiting the environment. Victims receive a 3-day deadline to respond, with explicit threats to call and email the target's employees and external clients directly, publish stolen archives on the LEAKEDDATA leak site, and expose victims to regulatory fines and client lawsuits. The group operates fast-flux DNS infrastructure using residential proxy networks across Latin America, Eastern Europe, Central Asia, the Middle East, and Asia, making takedowns difficult.
A particularly alarming evolution is the group's use of physical in-person intrusions. When remote social engineering fails, the group sends individuals to the victim's physical office location posing as IT technicians needing to "image the device" or create local backups. Once granted physical access, they exfiltrate corporate data directly to external USB storage devices. The FBI confirmed this tactic in a Cyber Flash Alert (IC3 CSA 2026/260526), and CNN reported in June 2026 on a similar incident where a law firm executive received a vishing call and an alleged IT visitor physically appeared at the
Target sectors: legal, financial-services, insurance, health
Target regions: united states of america
Timeline
- SilentRansomGroup (as UNC3753/Luna Moth) first observed active, originating from the Ryuk/Conti ransomware syndicate, initially deploying LOCKBIT.BLACK ransomware
- FBI observes SRG escalating tactics to include in-person physical office intrusions — sending individuals posing as IT technicians to law firm offices and exfiltrating data via USB storage devices
- FBI issues Cyber Flash Alert (IC3 CSA 2026/260526) specifically warning US law firms about Silent Ransom Group targeting with callback phishing, RMM tool abuse, and physical intrusion tactics
- SilentRansomGroup conducts its first known attack on Troutman Pepper Locke (approximate date; within one year of the August 2026 repeat attack). The group claimed this first intrusion was accomplished via physical office access with data exfiltration via USB storage devices
- Mandiant identifies a campaign targeting dozens of US law firms and professional services organizations over January through May 2026, attributed to UNC3753/SilentRansomGroup
- BleepingComputer publishes detailed analysis of SRG's fake IT support call campaigns targeting law firms; Mandiant/Google Cloud publishes deep technical analysis of the UNC3753 attack lifecycle
- Cloud Security Alliance publishes research note on UNC3753 detailing the group's vishing and physical intrusion tactics, confirming at least 38 law firms and over 100 total organizations victimized
- CNN reports on SRG's physical intrusion tactics, describing how cybercriminals hire individuals to physically visit law firm offices posing as IT support, with at least one documented incident where the impersonator fled when approached
- SilentRansomGroup lists Troutman Pepper Locke on its LEAKEDDATA leak site (business-data-leaks[.]com), detected by ThreatMon at 22:51 UTC. The group states: '2nd time we attacked them in a year (first time through physical intrusion), will continue our attacks'
- HookPhish and UnderCode News publish coverage of the Troutman Pepper Locke ransomware listing. No official statement from the firm has been issued. The nature and scope of accessed data remain unconfirmed by independent sources
Detections & IOCs
As of 2026-09-03, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 22 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1566.004, T1133, T1204.002, T1059.003, T1059.001, T1053.005, T1036.005, T1685, T1685.005, T1553.002