Silent Ransom Group Targets US Law Firms with Rapid Extortion Attacks
Want more insights like this?
A threat group called Silent Ransom (also tracked as UNC3753, Luna Moth and Chatty Spider) has been hitting US law, financial and professional services firms with a slick social engineering campaign between January and May 2026, according to Google's Mandiant division.
The attacks start with a clean invoice email — no malicious attachment — followed by a phone call from someone posing as internal IT or security. Victims are talked into a Zoom or Teams screen-share and into installing AnyDesk, Zoho Assist or similar remote access tools. The FBI warned separately in May that group members have also shown up at offices in person, posing as IT staff to reimage machines while plugging in USB drives to take data directly.
Once inside, the group moves fast — sometimes from initial contact to extortion demand in under an hour, with demands arriving within 30 minutes of the data being taken. Ransom notes come with a three-day deadline and threats to notify employees, partners and customers, and to go public.
Mandiant's advice: train staff on vishing, tighten conditional access for remote sessions, and lock down which RMM and screen-sharing tools can run at all.
Source: Dark Reading