Silent Ransom Group (Luna Moth) Targets US Law Firms via IT Support Impersonation and Physical Intrusion

Silent Ransom Group (Luna Moth) Targets US Law Firms via IT (TL-2026-2176) is a high-severity ransomware operation, first published 2026-08-28. It is attributed to Silent Ransom Group with high confidence, maps to 17 MITRE ATT&CK techniques (T1005, T1036.005, T1039), and is covered by 9 detection rules and 24 indicators of compromise.

Key facts for TL-2026-2176

Threat ID
TL-2026-2176
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
2026-08-28
Last reviewed
2026-08-28
Attribution
Silent Ransom Group
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
legal, law-firms, insurance, finance, accounting, health
Target regions
united states of america
Detection rules
9
Indicators of compromise
24

Malware and tooling in Silent Ransom Group (Luna Moth) Targets US Law Firms via IT

Malware and tooling: AnyDesk, AnyDesk, Atera, Microsoft Quick Assist, Quick Assist, Rclone - S1040, Reamaze Helpdesk, RustDesk, Splashtop, SuperOps, Syncro, WinSCP

Silent Ransom Group (SRG), aka Luna Moth and Chatty Spider, is running an active callback-phishing and vishing campaign against US law firms, impersonating IT helpdesk staff by phone and email to obtain remote access via legitimate RMM tools, then escalating to physical on-site intrusion when remote tactics fail. The group exfiltrates sensitive data (no encryption) and extorts victims for multi-million-dollar payments, including a disclosed $20 million demand in May 2026.

How Silent Ransom Group (Luna Moth) Targets US Law Firms via IT works

Silent Ransom Group is a financially motivated data-extortion actor that split from the Conti ransomware syndicate in March 2022 and grew out of the earlier BazarCall/BazarBackdoor callback-phishing operation. Rather than deploying ransomware encryptors, SRG steals sensitive files and threatens public disclosure unless paid. Since Spring 2023 the group has consistently targeted US-based law firms, with secondary targeting of insurance, finance, healthcare, and accounting organizations, prizing the high extortion leverage of privileged legal and client data.

The group's initial access relies on telephone-oriented attack delivery (TOAD): phishing emails disguised as subscription or online-class invoices instruct the recipient to call a helpdesk number to dispute a pending charge, or attackers cold-call employees directly claiming to be internal IT staff. Both paths funnel the victim into a live phone conversation where the actor talks them into joining a remote-support session and installing a legitimate remote monitoring and management (RMM) tool — observed tools include Zoho Assist, Syncro, SuperOps, Atera, AnyDesk, Splashtop, RustDesk, and Microsoft Quick Assist. Because these are digitally signed, widely used administration tools, the technique evades both signature-based and behavioral detection and leaves few forensic artifacts.

EclecticIQ assessed with high confidence (March 2025) that SRG had registered at least 37 typosquatted helpdesk domains through GoDaddy (patterns such as "[company]-helpdesk[.]com") to support the callback lures. Around March 2025 the group's tradecraft shifted further toward direct, unsolicited vishing calls rather than waiting for victims to dial in, and beginning in Spring 2025/2026 SRG began sending an operative to physically visit a target's office posing as IT/support staff, where they insert USB storage devices or external drives directly into workstations to image data when remote access is blocked or insufficient — a tactic the FBI's May 2026 Flash Report (FLASH-20260526-01) confirmed as an active, escalating technique.

Once access is established, SRG performs minimal privilege escalation and searches local files and network shares for sensitive material (client files, case notes, financial records, regulatory correspondence), then exfiltrates it using WinSCP (including a portable, non-admin variant) over SFTP, or Rclone — sometimes hidden or renamed to evade detection — to cloud storage such as MEGA, Google Drive, and Microsoft OneDrive. Persistence, where obtained, has used Syncro. Following exfiltration, SRG sends extortion emails and places direct phone calls to employees and even clients to apply pressure, demanding payment (historically 2-78 BTC, and $1-8 million USD in FBI-reported cases, with a $20 million payment from an unnamed US law firm disclosed in May 2026) and threatening to publish data on its clearweb leak site (business-data-leaks[.]com per the FBI Flash Report).

The FBI and IC3 have issued at least two public advisories (May 2025 and May 26, 2026) as reported intrusion activity accelerated, with Mandiant documenting a concentrated wave of law-firm breaches between January and May 2026.

MITRE ATT&CK techniques used in TL-2026-2176

Collection

T1005 Data from Local System; T1039 Data from Network Shared Drive

Defense Evasion

T1036.005 Match Legitimate Resource Name or Location; T1684.001 Impersonation

Exfiltration

T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol; T1052.001 Exfiltration Over Physical Medium: Exfiltration over USB; T1567.002 Exfiltration to Cloud Storage

Execution

T1204.001 User Execution: Malicious Link

Command and Control

T1219 Remote Access Tools

Initial Access

T1566.001 Phishing: Spearphishing Attachment; T1566.004 Phishing: Spearphishing Voice

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1588.002 Obtain Capabilities: Tool

Reconnaissance

T1589.002 Gather Victim Identity Information: Email Addresses; T1591 Gather Victim Org Information; T1598.004 Phishing for Information: Spearphishing Voice

Impact

T1657 Financial Theft

Remediation for Silent Ransom Group (Luna Moth) Targets US Law Firms via IT

Immediate actions

  • Implement mandatory callback-verification protocols before any employee installs remote-access/RMM software, using an internal directory number rather than a number provided in an email or by the caller
  • Block outbound access to known unauthorized RMM installer domains and binaries not on an organizational allowlist
  • Alert front-desk, reception, and physical-security staff to verify identity and IT-ticket numbers before granting building or workstation access to any 'IT support' visitor
  • Monitor for and restrict USB/removable-media mounting on workstations in sensitive departments (legal, finance)

Workarounds

  • Restrict local admin rights so unauthorized RMM tools cannot install with elevated privileges, forcing attackers into detectable portable/non-admin tool use
  • Require identity verification (photo ID plus IT ticket confirmation) for any in-person device service visit

Longer-term hardening

  • Deploy application allowlisting to restrict execution of RMM tools to an approved, IT-managed set (Zoho Assist, Syncro, SuperOps, Atera, AnyDesk, Splashtop, RustDesk, Quick Assist all observed abused)
  • Deploy DLP and egress monitoring for WinSCP/SFTP and Rclone traffic to cloud storage providers (MEGA, Google Drive, OneDrive)
  • Run recurring vishing/callback-phishing awareness training specifically modeled on TOAD (telephone-oriented attack delivery) scenarios
  • Establish an incident response playbook for extortion-only (non-encryption) intrusions, including legal/PR coordination given SRG's practice of contacting employees and clients directly

Timeline of Silent Ransom Group (Luna Moth) Targets US Law Firms via IT

  • Silent Ransom Group (Luna Moth) splits from the Conti ransomware syndicate as Conti collapses, pivoting from BazarCall/BazarBackdoor callback operations to standalone data-extortion attacks.
  • SRG shifts primary targeting focus to US-based law firms, exploiting the high extortion leverage of privileged legal and client data.
  • SRG tradecraft shifts toward direct, unsolicited vishing calls impersonating internal IT staff rather than waiting for victims to call back.
  • EclecticIQ assesses with high confidence that Luna Moth has registered at least 37 typosquatted helpdesk domains via GoDaddy to support callback-phishing lures.
  • Security media (BleepingComputer, The Hacker News, IT Pro) report on Luna Moth's callback-phishing campaign against law firms and its EclecticIQ-documented domain infrastructure.
  • FBI and IC3 issue their first public cyber alert on Silent Ransom Group targeting US law firms.
  • Initial reconnaissance and targeting activity for a new wave of SRG intrusions is observed in early April 2026.
  • First confirmed intrusions of the 2026 wave are reported in late April 2026, including escalation to physical on-site intrusion (operatives posing as IT staff inserting USB/storage devices).
  • An unnamed US law firm pays a reported $20 million ransom to Silent Ransom Group, the largest disclosed single payment in the campaign.
  • FBI issues Flash Report FLASH-20260526-01 (TLP:CLEAR), confirming physical intrusion as an active SRG tactic and naming the group's clearweb leak site business-data-leaks[.]com.
  • S-RM publishes its Cyber Intelligence Briefing covering the ongoing Silent Ransom Group campaign against US law firms, the source of this threat record.

Sources cited for Silent Ransom Group (Luna Moth) Targets US Law Firms via IT

More in ransomware

Detection coverage for TL-2026-2176

As of 2026-08-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2176 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats