UNC3753 Escalates: From Vishing Calls to Physical Office Intrusions at US Legal and Financial Firms
ID: cd685d77-8913-5d38-b66d-6ead37a78e5c
STIX ID: report--cd685d77-8913-5d38-b66d-6ead37a78e5c
Feed Name: Security Affairs
UNC3753 (aka Luna Moth / Silent Ransom Group) is running an active extortion campaign (Jan–May 2026) targeting U.S. law firms, financial services, and professional services: operators use pretexting and vishing to coerce employees into screen-sharing or installing legitimate RMM tools, access corporate VDIs and document repositories (iManage, SharePoint), rapidly search for high-value documents (W‑2s, W‑9s, SSNs, client agreements), exfiltrate data via WinSCP, Rclone or cloud drives, and issue extortion demands; when remote social engineering fails, the group has escalated to sending individuals to offices to plug USB drives into devices. Google Mandiant, GTIG, Resecurity, and the FBI have published reports and IOCs; recommended mitigations include blocking unauthorized RMM, enforcing conditional access and MFA, disabling USB mass storage, monitoring for bulk searches, visitor verification/escorts, and targeted staff training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
