UNC3753 Vishing Campaign Targets US Law Firms for Extortion
ID: aaba9e66-8585-593f-bb2a-94aa348987dd
STIX ID: report--aaba9e66-8585-593f-bb2a-94aa348987dd
Feed Name: securityonline.info
Mandiant reports an active UNC3753 (aka Luna Moth / Chatty Spider) vishing campaign (Jan–May 2026) targeting US law firms and financial services: actors use generic invoice emails to set a pretext, call employees posing as IT to initiate screen-sharing, push installation of commercial RMM (AnyDesk, Bomgar, Zoho Assist), search network/OneDrive/iManage for sensitive documents, exfiltrate data via WinSCP, Rclone or cloud uploads, and rapidly send extortion demands and publish stolen data on a LEAKEDDATA site; mitigation guidance focuses on verification of helpdesk requests, RMM restrictions, and monitoring for suspicious search and file-sharing activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
