logo

Silent Ransom Group “Call-back” Phishing Campaign

ID: 3996745e-316d-5f56-939d-2d0b0d128e30

STIX ID: report--3996745e-316d-5f56-939d-2d0b0d128e30

Feed Name: Arctic Wolf Blog

Threat Score
70/100

Date Published: 2025-04-10

Date Updated: 2026-04-27

...
...

Arctic Wolf reports an uptick in activity from the Silent Ransom Group targeting the legal industry using call-back phishing and vishing: attackers impersonate services to prompt victims to call and then social-engineer them into installing remote-access tools (Zoho Assist, AnyDesk), exfiltrate sensitive data (often via SFTP/WinSCP to private hosts like Hostwinds), and extort victims with threats to leak or sell stolen data. The bulletin recommends restricting outbound SFTP (port 22), uninstalling/unapproved RMM tools, and implementing vishing-focused security awareness training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.