logo

Silent Ransom Group targets law firms with fake IT support calls

ID: e05f7ff3-34ad-523e-8fbd-37a7151046f4

STIX ID: report--e05f7ff3-34ad-523e-8fbd-37a7151046f4

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-06-07

Date Updated: 2026-06-07

Author: Lawrence Abrams

...
...

Mandiant and FBI reporting shows the Silent Ransom Group (UNC3753) is actively targeting U.S. law firms and professional services with invoice‑themed callback phishing and impersonation of IT staff to initiate remote support sessions, install remote access tools (AnyDesk, Zoho Assist, Bomgar, SuperOps), and rapidly exfiltrate sensitive legal and financial files (using WinSCP/Rclone); attackers then issue fast, aggressive extortion demands and publish stolen data on fast‑flux protected leak sites. The advisory highlights in‑person imaging incidents, phishing domain patterns, use of privnote to hide commands, and recommends strict verification for IT interactions, limiting remote access, enforcing MFA, restricting USBs, and employee training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.