logo

FBI Warns Silent Ransom Group Targeting U.S. Law Firms

ID: f61c3e51-25c7-5ebf-b2cb-53154d23ab3d

STIX ID: report--f61c3e51-25c7-5ebf-b2cb-53154d23ab3d

Feed Name: Cyble Blog

Threat Score
72/100

Date Published: 2025-10-21

Date Updated: 2026-07-16

...
...

The FBI and Cyble warn that the Silent Ransom Group (SRG) is escalating operations against U.S. law firms by using callback phishing and direct phone-based social engineering to trick employees into installing legitimate remote management tools (Zoho Assist, AnyDesk, Syncro, etc.), then exfiltrating sensitive data with tools like WinSCP and Rclone and demanding ransoms (reported up to $800,000). The group leaves minimal digital footprints, relies on call centers and impersonation of IT staff, and defenders are advised to strengthen employee training, enforce strict IT authentication, limit remote-access privileges, monitor for unauthorized RMM/transfer tools, deploy EDR, require MFA, and maintain isolated backups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.