logo

Silent Ransom Group (SRG): Uncovering DNS Fast Flux Infrastructure

ID: 68128ecf-cc84-50ad-abcb-edbb4e0c35b5

STIX ID: report--68128ecf-cc84-50ad-abcb-edbb4e0c35b5

Feed Name: DataBreaches.Net

Threat Score
75/100

Date Published: 2026-06-07

Date Updated: 2026-06-08

Author: Dissent

...
...

Resecurity's analysis and related reporting identify the 'Silent Ransom Group' (SRG) as an active extortion-focused criminal actor targeting U.S. law firms and other sectors. The group employs social engineering and in-person physical intrusions to steal data and publishes stolen data on Clearnet Data Leak Sites while hiding its infrastructure using DNS Fast Flux backed by a geographically distributed network of compromised IoT and CPE devices across Latin America, Eastern Europe, Central Asia, Middle East/Africa, East Asia and the Caribbean; law enforcement agencies (including the FBI) and multiple national cybersecurity organizations have issued advisories about the threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.