logo

UNC3753 Vishing Campaign Targets US Law Firms for Extortion

ID: aaba9e66-8585-593f-bb2a-94aa348987dd

STIX ID: report--aaba9e66-8585-593f-bb2a-94aa348987dd

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-06-15

Date Updated: 2026-06-15

Author: Do Son

...
...

Mandiant reports an active UNC3753 (aka Luna Moth / Chatty Spider) vishing campaign (Jan–May 2026) targeting US law firms and financial services: actors use generic invoice emails to set a pretext, call employees posing as IT to initiate screen-sharing, push installation of commercial RMM (AnyDesk, Bomgar, Zoho Assist), search network/OneDrive/iManage for sensitive documents, exfiltrate data via WinSCP, Rclone or cloud uploads, and rapidly send extortion demands and publish stolen data on a LEAKEDDATA site; mitigation guidance focuses on verification of helpdesk requests, RMM restrictions, and monitoring for suspicious search and file-sharing activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.