logo

If you don't fall for these extortionists' calls, they'll show up with USB sticks

ID: 1020990a-4cdd-55f1-bb11-41b4a023552f

STIX ID: report--1020990a-4cdd-55f1-bb11-41b4a023552f

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-06-05

Date Updated: 2026-06-06

...
...

Google Mandiant reports that UNC3753 (also tracked as Luna Moth / Silent Ransom Group) has targeted dozens of US banks, law firms, and professional services firms using invoice-themed phishing to initiate phone-based helpdesk impersonation, remote screen-sharing and VDI abuse; when social engineering fails, attackers have attempted in-person physical intrusions to steal data via USB. The group conducts rapid intrusions (sometimes completing theft-to-extortion within hours), targets legal and financial documents containing PII and tax records, uses tools like portable WinSCP/Rclone or victim browser uploads to exfiltrate data, and issues extortion demands within roughly 30 minutes of exfiltration; the report includes IOCs and recommended mitigations (visitor controls, conditional access, and blocking unauthorized remote support utilities).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.