logo

FBI Alerts on Silent Ransom Group Targeting Law Firms

ID: 8e14a23f-b27f-55f2-9d4b-4a94dca2b2d9

STIX ID: report--8e14a23f-b27f-55f2-9d4b-4a94dca2b2d9

Feed Name: Halcyon Blog

Threat Score
78/100

Date Published: 2025-05-29

Date Updated: 2026-04-28

...
...

**Executive Summary:** The FBI warns that the Silent Ransom Group (SRG, aka Luna Moth/Chatty Spider/UNC3753) has been targeting U.S. law firms since 2022 using callback phishing and direct phone-based social engineering to persuade victims to install legitimate remote access tools (e.g., AnyDesk, Zoho Assist), then exfiltrate sensitive data via WinSCP or disguised Rclone before threatening publication on leak sites; the group leaves minimal forensic traces, often avoids privilege escalation, and relies on social engineering and legitimate tooling to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.