logo

Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms

ID: 4e7b5f6f-1248-5d02-a58d-2d7174998cf7

STIX ID: report--4e7b5f6f-1248-5d02-a58d-2d7174998cf7

Feed Name: Threat Intelligence

Threat Score
75/100

Date Published: 2026-06-05

Date Updated: 2026-06-06

Author: Mandiant

...
...

GTIG assesses that UNC3753 (aka Luna Moth / Chatty Spider / Silent Ransom Group) conducts financially motivated extortion and data theft against U.S. legal and professional services organizations using social-engineering (phone-based vishing), RMM tools, and phishing infrastructure; the group has escalated tactics to include in-person physical intrusions to exfiltrate data to removable media. The report provides attribution rationale, lists a data-leak site and IOCs, and offers mitigations covering user education, physical access controls, RMM/app whitelisting, removable-media hardening, and network/egress monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.