Silent Ransom Group Hits US Law Firms in Escalating Extortion Attacks
ID: 1da6d229-143b-5e50-ae35-602e69f69612
STIX ID: report--1da6d229-143b-5e50-ae35-602e69f69612
Feed Name: Dark Reading
Google/Mandiant attribute a financially motivated data-theft extortion campaign to UNC3753 (Silent Ransom/Luna Moth) that targeted dozens of US legal, professional, and financial firms between January and May 2026. Attackers use benign invoice-themed phishing followed by vishing and screen-sharing to persuade victims to install RMM tools or to access corporate VDI from BYOD devices, quickly locate and exfiltrate sensitive files (via WinSCP, Rclone, direct cloud uploads or drag-and-drop during screen-share), and then issue aggressive ransom threats within hours; recommended defenses include user education on vishing, conditional access for remote sessions, and strict controls on RMM and screen sharing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
