logo

Silent Ransom Group Uses In-Person IT Impersonation to Breach Systems

ID: 43710f57-2441-5dd2-b691-4217026bf4c2

STIX ID: report--43710f57-2441-5dd2-b691-4217026bf4c2

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

...
...

The FBI warns that the Silent Ransom Group (SRG / Luna Moth / Chatty Spider / UNC3753) has been targeting US law firms and other sectors since 2023 using evolved social engineering—impersonating IT staff by phone and in person to obtain remote desktop access or install storage devices—then exfiltrating sensitive data (via WinSCP, renamed Rclone, Google Drive/OneDrive, or external USB/hard drives) while avoiding detection by relying on legitimate management and remote-access tools; the alert includes recommended mitigations such as strict visitor authentication, phishing-resistant MFA, disabling external drive installation on sensitive endpoints, blocking port 22 where possible, and staff training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.