UNC3753 (Luna Moth / Silent Ransom Group) Vishing and Physical Intrusion Campaign Against US Law Firms — Threadlinqs Intelligence
As of 2026-08-24, UNC3753 (Luna Moth / Silent Ransom Group) Vishing and Physical Intrusion Campaign Against US Law Firms is a high-severity ransomware threat attributed to Luna Moth (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 22 indicators of compromise.
Threat ID: TL-2026-2127 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: Luna Moth · Russia · FINANCIAL
Mandiant/Google Threat Intelligence Group documents an ongoing financially motivated data-theft extortion campaign (January-May 2026) by UNC3753 (Luna Moth, Chatty Spider, Silent Ransom Group) against
UNC3753 — publicly tracked as Luna Moth, Chatty Spider, and Silent Ransom Group (SRG) — is a financially motivated, Russia-nexus extortion actor active since March 2022, formed in the wake of the Conti ransomware syndicate's collapse. The group does not encrypt victim data; it steals it and extorts victims with threats of public disclosure, a tactic it has run consistently even after briefly deploying LOCKBIT.BLACK ransomware in 2022 before deprioritizing encryption entirely.
The group's initial-access tradecraft has evolved through three distinct phases. From 2022 through early 2025 it ran callback-phishing campaigns: emails impersonating well-known subscription services (in the style of the related UNC2686/'BazarCall' cluster) prompted victims to call a fraudulent support number, where an operator talked them into installing remote-access software. In March 2025 the group pivoted to direct voice phishing (vishing): operators harvest employee phone numbers from public corporate websites, call posing as internal IT helpdesk or security staff, and use pretexts such as 'resolving a security issue' or a 'corporate data migration' to talk targets into a screen-sharing session (Zoom, Microsoft Teams, Microsoft Quick Assist, or Terminal Services) and then a commercial RMM install (AnyDesk, Bomgar, Zoho Assist, or SuperOps RMM, typically delivered via a curl/msiexec one-liner and a self-destructing privnote[.]com link). A parallel, generic 'invoice' email lure ('hello, here is the invcoie we talked about yesterday') is used to prime targets ahead of the call, without any malicious attachment or link.
Beginning around April 2025, and confirmed as an active, ongoing tactic by the FBI in a May 26, 2026 TLP:CLEAR FLASH alert (FLASH-20260526-01), the group escalated further: when remote social engineering fails, an operator physically travels to the victim's office, poses as an IT technician needing to 'image a device' or 'create a local backup,' and attempts to exfiltrate data directly onto a USB storage device.
Once inside an environment — remotely or physically — operators move with unusual speed: full lifecycle from initial contact to data theft and extortion has been observed within a single business day, with staging beginning inside the first hour. They compromise personal (BYOD) laptops via the screen-sharing session, then pivot into the corporate environment through native VDI clients (Windows365.exe, Citrix). Inside the environment they enumerate local directories, mapped network drives, and OneDrive folders, and run targeted keyword searches inside legal document-management systems (iManage) for W-2/W-9/1099 tax forms, audit files, client agreements, and Social Security numbers. Staged data is exfiltrated via drag-and-drop into actor-controlled consumer cloud storage (renamed to mimic the victim's branding), portable WinSCP, or Rclone over SFTP, or forwarded from the victim's own mailbox to actor-controlled consumer email addresses. In one documented incident, 1.7GB was pulled via OneDrive and 14.4GB via WinSCP.
Extortion follows within roughly 30 minutes of the actor exiting the environment: a letter (subject line pattern '[Victim Name] has lost confidential data of their clients. Very Important!') gives the victim a 3-day deadline, threatening direct outreach to employees and clients, publication on the group's leak site (business-data-leaks[.]com, also referenced as 'LEAKEDDATA DLS'), regulatory fines, and client lawsuits. Reported ransom demands range from roughly $1 million to as much as $20 million per victim. Public reporting attributes at least 38 law firms with data already posted to the leak site and estimates more than 100 total attacks in the campaign window, with named victims including Orrick, Herrington & Sutcliffe (data posted January 2026 after declining to pay), Jones Day, Wood Smith Henning & Berman (Q1 2026), and Ropers Majeski (claimed May 6, 2026).
Targeting is concentrated on US-based professional se
Target sectors: legal, professional services, financial services, insurance
Target regions: united states of america
Timeline
- UNC3753/Luna Moth/Silent Ransom Group emerges following the collapse of the Conti ransomware syndicate, initially running callback-phishing subscription-lure campaigns with TTP overlap to the UNC2686/'BazarCall' cluster.
- Group deploys LOCKBIT.BLACK ransomware in at least one incident before deprioritizing encryption in favor of data-theft-only extortion.
- Group shifts from subscription-themed callback-phishing lures to direct voice phishing (vishing), impersonating internal IT helpdesk staff over the phone.
- Group begins sending operators to physically enter victim offices posing as IT technicians when remote social-engineering attempts fail.
- FBI issues an earlier public-service announcement (PIN 052325) warning that Silent Ransom Group is targeting US law firms via vishing.
- Start of the January-May 2026 campaign window documented by Mandiant, showing dozens of US legal/financial/professional-services organizations targeted.
- Orrick, Herrington & Sutcliffe has stolen data posted to the group's leak site after declining to pay the ransom demand.
- Silent Ransom Group publicly claims responsibility for a breach at law firm Ropers Majeski.
- FBI publishes TLP:CLEAR FLASH alert FLASH-20260526-01, formally confirming Silent Ransom Group's escalation to in-person physical office intrusions for data exfiltration.
- Mandiant/Google Threat Intelligence Group publishes 'Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms,' detailing the full TTP chain, IOCs, and MITRE ATT&CK mapping for UNC3753.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 22 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1566.004, T1133, T1204.002, T1059.003, T1569.002, T1036.005, T1135, T1021.001, T1219, T1005