UNC3753 (Luna Moth / Silent Ransom Group) Vishing and Physical Intrusion Campaign Against US Law Firms
UNC3753 (Luna Moth / Silent Ransom Group) Vishing and (TL-2026-2127) is a high-severity ransomware operation, first published 2026-08-24. It is attributed to Luna Moth (Russia) with high confidence, affects N/A iManage document management deployments at US law firms, maps to 13 MITRE ATT&CK techniques (T1005, T1020, T1021.001), and is covered by 9 detection rules and 22 indicators of compromise.
Key facts for TL-2026-2127
- Threat ID
- TL-2026-2127
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-08-24
- Last reviewed
- 2026-08-24
- Attribution
- Luna Moth
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- legal, professional services, financial services, insurance
- Target regions
- united states of america
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in UNC3753 (Luna Moth / Silent Ransom Group) Vishing and
Malware and tooling: AnyDesk, LockBit 3.0 - S1202, AnyDesk, Bomgar, Rclone - S1040, SuperOps RMM, WinSCP, Zoho Assist
Mandiant/Google Threat Intelligence Group documents an ongoing financially motivated data-theft extortion campaign (January-May 2026) by UNC3753 (Luna Moth, Chatty Spider, Silent Ransom Group) against dozens of US legal, financial, and professional services firms. The actor impersonates IT helpdesk staff via phone to obtain remote access, exfiltrates data through commercial RMM tools, WinSCP, and Rclone, then extorts victims via a leak site. An FBI FLASH alert (FLASH-20260526-01) confirms the campaign escalated to in-person physical office intrusions when remote social engineering fails.
How UNC3753 (Luna Moth / Silent Ransom Group) Vishing and works
UNC3753 — publicly tracked as Luna Moth, Chatty Spider, and Silent Ransom Group (SRG) — is a financially motivated, Russia-nexus extortion actor active since March 2022, formed in the wake of the Conti ransomware syndicate's collapse. The group does not encrypt victim data; it steals it and extorts victims with threats of public disclosure, a tactic it has run consistently even after briefly deploying LOCKBIT.BLACK ransomware in 2022 before deprioritizing encryption entirely.
The group's initial-access tradecraft has evolved through three distinct phases. From 2022 through early 2025 it ran callback-phishing campaigns: emails impersonating well-known subscription services (in the style of the related UNC2686/'BazarCall' cluster) prompted victims to call a fraudulent support number, where an operator talked them into installing remote-access software. In March 2025 the group pivoted to direct voice phishing (vishing): operators harvest employee phone numbers from public corporate websites, call posing as internal IT helpdesk or security staff, and use pretexts such as 'resolving a security issue' or a 'corporate data migration' to talk targets into a screen-sharing session (Zoom, Microsoft Teams, Microsoft Quick Assist, or Terminal Services) and then a commercial RMM install (AnyDesk, Bomgar, Zoho Assist, or SuperOps RMM, typically delivered via a curl/msiexec one-liner and a self-destructing privnote[.]com link). A parallel, generic 'invoice' email lure ('hello, here is the invcoie we talked about yesterday') is used to prime targets ahead of the call, without any malicious attachment or link.
Beginning around April 2025, and confirmed as an active, ongoing tactic by the FBI in a May 26, 2026 TLP:CLEAR FLASH alert (FLASH-20260526-01), the group escalated further: when remote social engineering fails, an operator physically travels to the victim's office, poses as an IT technician needing to 'image a device' or 'create a local backup,' and attempts to exfiltrate data directly onto a USB storage device.
Once inside an environment — remotely or physically — operators move with unusual speed: full lifecycle from initial contact to data theft and extortion has been observed within a single business day, with staging beginning inside the first hour. They compromise personal (BYOD) laptops via the screen-sharing session, then pivot into the corporate environment through native VDI clients (Windows365.exe, Citrix). Inside the environment they enumerate local directories, mapped network drives, and OneDrive folders, and run targeted keyword searches inside legal document-management systems (iManage) for W-2/W-9/1099 tax forms, audit files, client agreements, and Social Security numbers. Staged data is exfiltrated via drag-and-drop into actor-controlled consumer cloud storage (renamed to mimic the victim's branding), portable WinSCP, or Rclone over SFTP, or forwarded from the victim's own mailbox to actor-controlled consumer email addresses. In one documented incident, 1.7GB was pulled via OneDrive and 14.4GB via WinSCP.
Extortion follows within roughly 30 minutes of the actor exiting the environment: a letter (subject line pattern '[Victim Name] has lost confidential data of their clients. Very Important!') gives the victim a 3-day deadline, threatening direct outreach to employees and clients, publication on the group's leak site (business-data-leaks[.]com, also referenced as 'LEAKEDDATA DLS'), regulatory fines, and client lawsuits. Reported ransom demands range from roughly $1 million to as much as $20 million per victim. Public reporting attributes at least 38 law firms with data already posted to the leak site and estimates more than 100 total attacks in the campaign window, with named victims including Orrick, Herrington & Sutcliffe (data posted January 2026 after declining to pay), Jones Day, Wood Smith Henning & Berman (Q1 2026), and Ropers Majeski (claimed May 6, 2026).
Targeting is concentrated on US-based professional services, with a strong emphasis on law firms (for privileged, high-leverage client data) and financial/insurance services. Mandiant and the FBI jointly recommend physical-access controls (visitor ID verification against pre-scheduled work orders, mandatory escort of technical personnel), RMM/screen-sharing application control, BYOD-aware conditional access restricting VDI/VPN to corporate-owned devices with MFA step-up, USB mass-storage lockdown via GPO/MDM, and application-level auditing (real-time bulk-download and search-spike alerting) on iManage, SharePoint, and corporate email.
MITRE ATT&CK techniques used in TL-2026-2127
Collection
Exfiltration
T1020 Automated Exfiltration; T1052.001 Exfiltration Over Physical Medium: Exfiltration over USB; T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
Lateral Movement
T1021.001 Remote Services: Remote Desktop Protocol
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location
Execution
T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1204.002 User Execution: Malicious File; T1569.002 System Services: Service Execution
Initial Access
T1133 External Remote Services; T1566.004 Phishing: Spearphishing Voice
Discovery
command-and-control
Affected products and versions in UNC3753 (Luna Moth / Silent Ransom Group) Vishing and
- N/A — iManage document management deployments at US law firms
Vulnerable versions: any deployment reachable via compromised VDI/RDP without additional MFA or bulk-access alerting - N/A — US professional, legal, financial, and insurance services organizations
Vulnerable versions: organizations lacking physical-visitor verification and RMM/screen-share application control
Remediation for UNC3753 (Luna Moth / Silent Ransom Group) Vishing and
Patches
- N/A — initial access is voice-phishing and in-person social engineering, not a software vulnerability; no vendor patch applies
Immediate actions
- Require official credentials and photo ID for any in-person IT/technician visit; verify against pre-scheduled work orders before granting building or device access
- Block unauthorized RMM and screen-sharing installers (AnyDesk, Bomgar, Zoho Assist, SuperOps RMM) via application allow-listing / Windows Defender Application Control or EDR
- Disable read/write for USB mass-storage devices via GPO/MDM on endpoints handling client data
- Restrict screen-control features in Zoom and Microsoft Teams to prevent unsolicited remote-control sessions
Workarounds
- Publish and enforce a single verified internal IT contact number; instruct staff to never accept remote-access instructions from an inbound caller claiming to be IT
- Mandate escort of all technical service personnel and log visitor IDs at reception
- Enforce MFA on iManage and other document-management repositories independent of network-level authentication
- Restrict removable and optical media on endpoints and BYOD systems that can reach VDI
Longer-term hardening
- Restrict VDI/VPN authentication to corporate-owned devices only, with MFA step-up for any BYOD-originated access attempt
- Enable full session logging with byte-transfer metrics on egress paths and monitor SSH/SFTP (port 22) from internal VDIs for WinSCP/Rclone transfer patterns
- Deploy real-time alerting for rapid file-search bursts and mass downloads inside iManage, SharePoint, and corporate email
- Run recurring vishing-specific awareness training that covers IT-helpdesk-impersonation pretexts and in-person 'technician' social engineering
Timeline of UNC3753 (Luna Moth / Silent Ransom Group) Vishing and
- UNC3753/Luna Moth/Silent Ransom Group emerges following the collapse of the Conti ransomware syndicate, initially running callback-phishing subscription-lure campaigns with TTP overlap to the UNC2686/'BazarCall' cluster.
- Group deploys LOCKBIT.BLACK ransomware in at least one incident before deprioritizing encryption in favor of data-theft-only extortion.
- Group shifts from subscription-themed callback-phishing lures to direct voice phishing (vishing), impersonating internal IT helpdesk staff over the phone.
- Group begins sending operators to physically enter victim offices posing as IT technicians when remote social-engineering attempts fail.
- FBI issues an earlier public-service announcement (PIN 052325) warning that Silent Ransom Group is targeting US law firms via vishing.
- Orrick, Herrington & Sutcliffe has stolen data posted to the group's leak site after declining to pay the ransom demand.
- Start of the January-May 2026 campaign window documented by Mandiant, showing dozens of US legal/financial/professional-services organizations targeted.
- Silent Ransom Group publicly claims responsibility for a breach at law firm Ropers Majeski.
- FBI publishes TLP:CLEAR FLASH alert FLASH-20260526-01, formally confirming Silent Ransom Group's escalation to in-person physical office intrusions for data exfiltration.
- Mandiant/Google Threat Intelligence Group publishes 'Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms,' detailing the full TTP chain, IOCs, and MITRE ATT&CK mapping for UNC3753.
Sources cited for UNC3753 (Luna Moth / Silent Ransom Group) Vishing and
- Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms
- FBI FLASH-20260526-01: Silent Ransom Group Impersonating IT Personnel Through Social Engineering
- FBI Cyber Alert: Silent Ransom Group Impersonating IT Personnel Through Social Engineering
- Google and FBI warn of ransomware group that sends fake IT workers to hack victims in person
- An Old Tactic Returns: Silent Ransom Group's Active Use of Physical Intrusion Against U.S. Law Firms
- Silent Ransom Group Sends Operatives Into Law Firm Offices: 38 Firms Already Leaked
- FBI warns of Luna Moth extortion attacks targeting law firms
- Hackers Are Calling Your Office: FBI Alerts Law Firms to Luna Moth's Stealth Phishing Campaign
- Silent Ransom Group Launches Vishing Attacks on Law Firms
- FBI Warns Silent Ransom Group Targeting U.S. Law Firms
- Silent Ransom Group Targeting Law Firms (FBI PIN 052325)
Threats related to UNC3753 (Luna Moth / Silent Ransom Group) Vishing and
- Troutman Pepper Locke LLP Data Theft Extortion by SilentRansomGroup (Repeat Attack Including Physical Intrusion)
- UNC3753 (Silent Ransom Group / Luna Moth) Escalation — Physical Office Intrusion & USB Data Exfiltration Against US Legal & Financial Services (FBI Flash CSA, 2026)
- Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753) — IT Support Impersonation Campaign Targeting US Law Firms (FBI FLASH Advisory, May 2026)
- Chaos Ransomware Group Claims 235GB PHI/Internal Document Leak from Healthcare Highways (Unconfirmed)
Detection coverage for TL-2026-2127
As of 2026-08-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2127 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.