Silent Ransom Group (Luna Moth) Targets US Law Firms via IT Support Impersonation and Physical Intrusion — Threadlinqs Intelligence
As of 2026-08-28, Silent Ransom Group (Luna Moth) Targets US Law Firms via IT Support Impersonation and Physical Intrusion is a high-severity ransomware threat attributed to Silent Ransom Group, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-2176 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: Silent Ransom Group · FINANCIAL
Silent Ransom Group (SRG), aka Luna Moth and Chatty Spider, is running an active callback-phishing and vishing campaign against US law firms, impersonating IT helpdesk staff by phone and email to
Silent Ransom Group is a financially motivated data-extortion actor that split from the Conti ransomware syndicate in March 2022 and grew out of the earlier BazarCall/BazarBackdoor callback-phishing operation. Rather than deploying ransomware encryptors, SRG steals sensitive files and threatens public disclosure unless paid. Since Spring 2023 the group has consistently targeted US-based law firms, with secondary targeting of insurance, finance, healthcare, and accounting organizations, prizing the high extortion leverage of privileged legal and client data.
The group's initial access relies on telephone-oriented attack delivery (TOAD): phishing emails disguised as subscription or online-class invoices instruct the recipient to call a helpdesk number to dispute a pending charge, or attackers cold-call employees directly claiming to be internal IT staff. Both paths funnel the victim into a live phone conversation where the actor talks them into joining a remote-support session and installing a legitimate remote monitoring and management (RMM) tool — observed tools include Zoho Assist, Syncro, SuperOps, Atera, AnyDesk, Splashtop, RustDesk, and Microsoft Quick Assist. Because these are digitally signed, widely used administration tools, the technique evades both signature-based and behavioral detection and leaves few forensic artifacts.
EclecticIQ assessed with high confidence (March 2025) that SRG had registered at least 37 typosquatted helpdesk domains through GoDaddy (patterns such as "[company]-helpdesk[.]com") to support the callback lures. Around March 2025 the group's tradecraft shifted further toward direct, unsolicited vishing calls rather than waiting for victims to dial in, and beginning in Spring 2025/2026 SRG began sending an operative to physically visit a target's office posing as IT/support staff, where they insert USB storage devices or external drives directly into workstations to image data when remote access is blocked or insufficient — a tactic the FBI's May 2026 Flash Report (FLASH-20260526-01) confirmed as an active, escalating technique.
Once access is established, SRG performs minimal privilege escalation and searches local files and network shares for sensitive material (client files, case notes, financial records, regulatory correspondence), then exfiltrates it using WinSCP (including a portable, non-admin variant) over SFTP, or Rclone — sometimes hidden or renamed to evade detection — to cloud storage such as MEGA, Google Drive, and Microsoft OneDrive. Persistence, where obtained, has used Syncro. Following exfiltration, SRG sends extortion emails and places direct phone calls to employees and even clients to apply pressure, demanding payment (historically 2-78 BTC, and $1-8 million USD in FBI-reported cases, with a $20 million payment from an unnamed US law firm disclosed in May 2026) and threatening to publish data on its clearweb leak site (business-data-leaks[.]com per the FBI Flash Report).
The FBI and IC3 have issued at least two public advisories (May 2025 and May 26, 2026) as reported intrusion activity accelerated, with Mandiant documenting a concentrated wave of law-firm breaches between January and May 2026.
Target sectors: legal, law-firms, insurance, finance, accounting, health
Target regions: united states of america
Timeline
- Silent Ransom Group (Luna Moth) splits from the Conti ransomware syndicate as Conti collapses, pivoting from BazarCall/BazarBackdoor callback operations to standalone data-extortion attacks.
- SRG shifts primary targeting focus to US-based law firms, exploiting the high extortion leverage of privileged legal and client data.
- EclecticIQ assesses with high confidence that Luna Moth has registered at least 37 typosquatted helpdesk domains via GoDaddy to support callback-phishing lures.
- SRG tradecraft shifts toward direct, unsolicited vishing calls impersonating internal IT staff rather than waiting for victims to call back.
- Security media (BleepingComputer, The Hacker News, IT Pro) report on Luna Moth's callback-phishing campaign against law firms and its EclecticIQ-documented domain infrastructure.
- FBI and IC3 issue their first public cyber alert on Silent Ransom Group targeting US law firms.
- Initial reconnaissance and targeting activity for a new wave of SRG intrusions is observed in early April 2026.
- First confirmed intrusions of the 2026 wave are reported in late April 2026, including escalation to physical on-site intrusion (operatives posing as IT staff inserting USB/storage devices).
- An unnamed US law firm pays a reported $20 million ransom to Silent Ransom Group, the largest disclosed single payment in the campaign.
- FBI issues Flash Report FLASH-20260526-01 (TLP:CLEAR), confirming physical intrusion as an active SRG tactic and naming the group's clearweb leak site business-data-leaks[.]com.
- S-RM publishes its Cyber Intelligence Briefing covering the ongoing Silent Ransom Group campaign against US law firms, the source of this threat record.
Detections & IOCs
As of 2026-09-04, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1591, T1589.002, T1598.004, T1583.001, T1588.002, T1566.001, T1566.004, T1204.001, T1684.001, T1036.005