Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Silent Ransom Group targets law firms with fake IT support calls

0
Medium
Vulnerability
Published: 06/07/2026 (06/07/2026, 14:09:19 UTC)
Source: Bleeping Computer

Description

The Silent Ransom Group extortion gang is actively targeting U.S.law firms and professional services organizations in social engineering attacks that often lead to data theft within hours of initial contact, according to a new report by cybersecurity firm Mandiant. [...]

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/07/2026, 21:48:17 UTC

Technical Analysis

The Silent Ransom Group (tracked as UNC3753, Luna Moth, Chatty Spider) targets U.S. law firms and professional services via social engineering campaigns that begin with invoice-themed phishing emails lacking malicious payloads. These emails prompt victims to call back attackers impersonating IT staff, who then conduct remote support sessions using platforms like Microsoft Teams or Zoom. During these sessions, attackers convince victims to install remote monitoring and management tools (e.g., AnyDesk, Zoho Assist), gaining initial network access. The group searches for sensitive documents on document management and cloud storage platforms, exfiltrating data using tools such as WinSCP or Rclone. Extortion demands follow rapidly, with a three-day deadline and threats to notify clients and regulators. The group also uses fast-flux DNS infrastructure to protect its leak sites. The FBI has reported related in-person data theft attempts. The group evolved from Ryuk and Conti ransomware affiliates and now focuses solely on data theft extortion.

Potential Impact

The threat actor gains unauthorized remote access to corporate networks of law firms and professional services organizations, leading to theft of highly sensitive client and corporate data including contracts, tax records, Social Security numbers, and merger/acquisition files. The rapid extortion demands and threats to expose stolen data pose significant reputational and regulatory risks to victims. The attacks can result in data breaches with potential legal and financial consequences. The use of fast-flux infrastructure complicates takedown efforts of the group's leak sites. The FBI's report of in-person data theft attempts further increases the risk of physical compromise of sensitive data.

Mitigation Recommendations

No official patch applies as this is a social engineering and operational threat rather than a software vulnerability. The FBI and Mandiant recommend implementing strict verification procedures for all IT support interactions to confirm legitimacy before granting access. Organizations should limit the use of remote access tools and enforce multi-factor authentication (MFA) to reduce unauthorized access risk. Employee training to recognize voice phishing and callback phishing tactics is critical. Restricting USB storage device usage can help mitigate in-person data theft risks. These mitigations address the specific tactics used by the Silent Ransom Group as described in the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.bleepingcomputer.com/news/security/silent-ransom-group-targets-law-firms-with-fake-it-support-calls/","fetched":true,"fetchedAt":"2026-06-07T21:47:53.404Z","wordCount":1330}

Threat ID: 6a25e712e29bf47b5042bf35

Added to database: 06/07/2026, 21:48:02 UTC

Last enriched: 06/07/2026, 21:48:17 UTC

Last updated: 07/26/2026, 13:04:03 UTC

Views: 101

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses