Silent Ransom Group (Luna Moth) Targets US Law Firms via IT Support Impersonation and Physical Intrusion
Silent Ransom Group (Luna Moth) Targets US Law Firms via IT (TL-2026-2176) is a high-severity ransomware operation, first published 2026-08-28. It is attributed to Silent Ransom Group with high confidence, maps to 17 MITRE ATT&CK techniques (T1005, T1036.005, T1039), and is covered by 9 detection rules and 24 indicators of compromise.
Key facts for TL-2026-2176
- Threat ID
- TL-2026-2176
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-08-28
- Last reviewed
- 2026-08-28
- Attribution
- Silent Ransom Group
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- legal, law-firms, insurance, finance, accounting, health
- Target regions
- united states of america
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in Silent Ransom Group (Luna Moth) Targets US Law Firms via IT
Malware and tooling: AnyDesk, AnyDesk, Atera, Microsoft Quick Assist, Quick Assist, Rclone - S1040, Reamaze Helpdesk, RustDesk, Splashtop, SuperOps, Syncro, WinSCP
Silent Ransom Group (SRG), aka Luna Moth and Chatty Spider, is running an active callback-phishing and vishing campaign against US law firms, impersonating IT helpdesk staff by phone and email to obtain remote access via legitimate RMM tools, then escalating to physical on-site intrusion when remote tactics fail. The group exfiltrates sensitive data (no encryption) and extorts victims for multi-million-dollar payments, including a disclosed $20 million demand in May 2026.
How Silent Ransom Group (Luna Moth) Targets US Law Firms via IT works
Silent Ransom Group is a financially motivated data-extortion actor that split from the Conti ransomware syndicate in March 2022 and grew out of the earlier BazarCall/BazarBackdoor callback-phishing operation. Rather than deploying ransomware encryptors, SRG steals sensitive files and threatens public disclosure unless paid. Since Spring 2023 the group has consistently targeted US-based law firms, with secondary targeting of insurance, finance, healthcare, and accounting organizations, prizing the high extortion leverage of privileged legal and client data.
The group's initial access relies on telephone-oriented attack delivery (TOAD): phishing emails disguised as subscription or online-class invoices instruct the recipient to call a helpdesk number to dispute a pending charge, or attackers cold-call employees directly claiming to be internal IT staff. Both paths funnel the victim into a live phone conversation where the actor talks them into joining a remote-support session and installing a legitimate remote monitoring and management (RMM) tool — observed tools include Zoho Assist, Syncro, SuperOps, Atera, AnyDesk, Splashtop, RustDesk, and Microsoft Quick Assist. Because these are digitally signed, widely used administration tools, the technique evades both signature-based and behavioral detection and leaves few forensic artifacts.
EclecticIQ assessed with high confidence (March 2025) that SRG had registered at least 37 typosquatted helpdesk domains through GoDaddy (patterns such as "[company]-helpdesk[.]com") to support the callback lures. Around March 2025 the group's tradecraft shifted further toward direct, unsolicited vishing calls rather than waiting for victims to dial in, and beginning in Spring 2025/2026 SRG began sending an operative to physically visit a target's office posing as IT/support staff, where they insert USB storage devices or external drives directly into workstations to image data when remote access is blocked or insufficient — a tactic the FBI's May 2026 Flash Report (FLASH-20260526-01) confirmed as an active, escalating technique.
Once access is established, SRG performs minimal privilege escalation and searches local files and network shares for sensitive material (client files, case notes, financial records, regulatory correspondence), then exfiltrates it using WinSCP (including a portable, non-admin variant) over SFTP, or Rclone — sometimes hidden or renamed to evade detection — to cloud storage such as MEGA, Google Drive, and Microsoft OneDrive. Persistence, where obtained, has used Syncro. Following exfiltration, SRG sends extortion emails and places direct phone calls to employees and even clients to apply pressure, demanding payment (historically 2-78 BTC, and $1-8 million USD in FBI-reported cases, with a $20 million payment from an unnamed US law firm disclosed in May 2026) and threatening to publish data on its clearweb leak site (business-data-leaks[.]com per the FBI Flash Report).
The FBI and IC3 have issued at least two public advisories (May 2025 and May 26, 2026) as reported intrusion activity accelerated, with Mandiant documenting a concentrated wave of law-firm breaches between January and May 2026.
MITRE ATT&CK techniques used in TL-2026-2176
Collection
T1005 Data from Local System; T1039 Data from Network Shared Drive
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location; T1684.001 Impersonation
Exfiltration
T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol; T1052.001 Exfiltration Over Physical Medium: Exfiltration over USB; T1567.002 Exfiltration to Cloud Storage
Execution
T1204.001 User Execution: Malicious Link
Command and Control
Initial Access
T1566.001 Phishing: Spearphishing Attachment; T1566.004 Phishing: Spearphishing Voice
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1588.002 Obtain Capabilities: Tool
Reconnaissance
T1589.002 Gather Victim Identity Information: Email Addresses; T1591 Gather Victim Org Information; T1598.004 Phishing for Information: Spearphishing Voice
Impact
Remediation for Silent Ransom Group (Luna Moth) Targets US Law Firms via IT
Immediate actions
- Implement mandatory callback-verification protocols before any employee installs remote-access/RMM software, using an internal directory number rather than a number provided in an email or by the caller
- Block outbound access to known unauthorized RMM installer domains and binaries not on an organizational allowlist
- Alert front-desk, reception, and physical-security staff to verify identity and IT-ticket numbers before granting building or workstation access to any 'IT support' visitor
- Monitor for and restrict USB/removable-media mounting on workstations in sensitive departments (legal, finance)
Workarounds
- Restrict local admin rights so unauthorized RMM tools cannot install with elevated privileges, forcing attackers into detectable portable/non-admin tool use
- Require identity verification (photo ID plus IT ticket confirmation) for any in-person device service visit
Longer-term hardening
- Deploy application allowlisting to restrict execution of RMM tools to an approved, IT-managed set (Zoho Assist, Syncro, SuperOps, Atera, AnyDesk, Splashtop, RustDesk, Quick Assist all observed abused)
- Deploy DLP and egress monitoring for WinSCP/SFTP and Rclone traffic to cloud storage providers (MEGA, Google Drive, OneDrive)
- Run recurring vishing/callback-phishing awareness training specifically modeled on TOAD (telephone-oriented attack delivery) scenarios
- Establish an incident response playbook for extortion-only (non-encryption) intrusions, including legal/PR coordination given SRG's practice of contacting employees and clients directly
Timeline of Silent Ransom Group (Luna Moth) Targets US Law Firms via IT
- Silent Ransom Group (Luna Moth) splits from the Conti ransomware syndicate as Conti collapses, pivoting from BazarCall/BazarBackdoor callback operations to standalone data-extortion attacks.
- SRG shifts primary targeting focus to US-based law firms, exploiting the high extortion leverage of privileged legal and client data.
- SRG tradecraft shifts toward direct, unsolicited vishing calls impersonating internal IT staff rather than waiting for victims to call back.
- EclecticIQ assesses with high confidence that Luna Moth has registered at least 37 typosquatted helpdesk domains via GoDaddy to support callback-phishing lures.
- Security media (BleepingComputer, The Hacker News, IT Pro) report on Luna Moth's callback-phishing campaign against law firms and its EclecticIQ-documented domain infrastructure.
- FBI and IC3 issue their first public cyber alert on Silent Ransom Group targeting US law firms.
- Initial reconnaissance and targeting activity for a new wave of SRG intrusions is observed in early April 2026.
- First confirmed intrusions of the 2026 wave are reported in late April 2026, including escalation to physical on-site intrusion (operatives posing as IT staff inserting USB/storage devices).
- An unnamed US law firm pays a reported $20 million ransom to Silent Ransom Group, the largest disclosed single payment in the campaign.
- FBI issues Flash Report FLASH-20260526-01 (TLP:CLEAR), confirming physical intrusion as an active SRG tactic and naming the group's clearweb leak site business-data-leaks[.]com.
- S-RM publishes its Cyber Intelligence Briefing covering the ongoing Silent Ransom Group campaign against US law firms, the source of this threat record.
Sources cited for Silent Ransom Group (Luna Moth) Targets US Law Firms via IT
- Cyber Intelligence Briefing - 12 June 2026
- Silent Ransom Group Impersonating IT Personnel through Social Engineering (CSA)
- FBI Flash Report TLP Clear: Silent Ransom Group Impersonating IT Personnel
- Silent Ransom Group Targeting Law Firms
- Threat Assessment: Luna Moth Callback Phishing Campaign
- Luna Moth extortion hackers pose as IT help desks to breach US firms
- FBI warns of Luna Moth extortion attacks targeting law firms
- Silent Ransom Group (Luna Moth) Extortion Attacks Target US Law Firms via Remote Access Tools and Social Engineering
- Luna Moth (Threat Actor)
- An Old Tactic Returns: Silent Ransom Group's Active Use of Physical Intrusion Against U.S. Law Firms
- Luna Moth Targets US Law Firms: $20M Ransom, 100+ Attacks
- Hackers Are Calling Your Office: FBI Alerts Law Firms to Luna Moth's Stealth Phishing Campaign
- This hacker group is posing as IT helpdesk workers to target enterprises
More in ransomware
- Hyadina Rebrands Beast Ransomware as 'GodDamn' and Uses PoisonX Signed Kernel Driver to Disable Endpoint Defenses
- DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD Files with Defense Mil-Spec References
- Vexy Ransomware hits Mega Velocity — 46.68 GB exfiltrated, double extortion
- Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)
- Vexy Ransomware (RaaS) claims Sancity (sancity.in) — Indian real estate/construction group; 130 MB data exfiltration alleged
Detection coverage for TL-2026-2176
As of 2026-08-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2176 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.