#unc3753
Die Google Threat Intelligence Group warnt vor der Gruppe UNC3753. Die Angreifer geben sich vor Ort als IT-Techniker aus, um Daten per USB-Stick zu stehlen. #Security
Google warnt: Angreifer geben sich als IT-Techniker aus und betreten Büros
Die Google Threat Intelligence Group warnt vor der Gruppe UNC3753. Die Angreifer geben sich vor Ort als IT-Techniker aus, um Daten per USB-Stick zu stehlen.
www.heise.de
June 6, 2026 at 11:51 AM
A ransomware group known as Luna Moth (Silent, UNC3753, or Storm-0252) is using callback phishing techniques to target US organizations in the legal and financial sectors

blog.eclecticiq.com/from-callbac...
May 1, 2025 at 11:12 AM
UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign
UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign
thehackernews.com
June 8, 2026 at 9:01 AM
There are FBI bulletins about the group targeting law firms since last summer and all indications are that the people behind the group are based in Russia.
www.fbi.gov/file-reposit...
Silent Ransom Group Targeting Law Firms | Federal Bureau of Investigation
The cyber threat actor Silent Ransom Group (SRG), also known as Luna Moth, Chatty Spider, and UNC3753, is targeting law firms using information technology (IT) themed social engineering calls, then se...
www.fbi.gov
April 7, 2026 at 8:14 PM
UNC3753 Escalates: From Vishing Calls to Physical Office Intrusions at US Legal and Financial Firms
UNC3753 Escalates: From Vishing Calls to Physical Office Intrusions at US Legal and Financial Firms
UNC3753 phones staff posing as IT, hijacks screen sessions, steals sensitive legal files, and now sends operatives physically into offices to plug in USB drives.
securityaffairs.com
June 8, 2026 at 11:36 AM
UNC3753 Escalates: From Vishing Calls to Physical Office Intrusions at US Legal and Financial Firms

UNC3753 phones staff posing as IT, hijacks screen sessions, steals sensitive legal files, and now sends operatives physically into offices to plug in USB drives. Google Mandiant an…
#hackernews #news
UNC3753 Escalates: From Vishing Calls to Physical Office Intrusions at US Legal and Financial Firms
UNC3753 phones staff posing as IT, hijacks screen sessions, steals sensitive legal files, and now sends operatives physically into offices to plug in USB drives. Google Mandiant and the Google Threat Intelligence Group published a detailed report documenting an active extortion campaign carried out by the cybercrime group UNC3753 (aka Luna Moth, Chatty Spider, and […]
securityaffairs.com
June 9, 2026 at 1:37 AM
Dozens of U.S. firms were targeted with a simple playbook:
> Fake invoice email
> Fake IT support call
> Screen share
> Remote access tool
> Data theft
> Extortion demand within 30mn
UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign

thehackernews.com/2026/06/unc3...
UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign
UNC3753 hit dozens of U.S. firms in Jan-May 2026 using vishing and RMM tools, driving rapid data theft extortion.
thehackernews.com
June 8, 2026 at 7:55 AM
UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
June 8, 2026 at 9:59 AM
"Threat actors initiate phone conversations posing as IT support and convince targets to host screen-sharing sessions and download remote monitoring and management (RMM) utilities."

thehackernews.com/2026/06/unc3...

#Vishing #Extortion
UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign
UNC3753 hit dozens of U.S. firms in Jan-May 2026 using vishing and RMM tools, driving rapid data theft extortion.
thehackernews.com
June 8, 2026 at 7:54 AM
UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign

Cybersecurity researchers have disclosed details of a financially motivated data theft extortion campaign that has targeted dozens of organizations across professional, legal, and financial service…
#hackernews #news
UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign
Cybersecurity researchers have disclosed details of a financially motivated data theft extortion campaign that has targeted dozens of organizations across professional, legal, and financial services in the U.S. between January and May 2026. The activity has been attributed by Google Mandiant and Google Threat Intelligence Group (GTIG) to a threat actor dubbed UNC3753, which is also known as
thehackernews.com
June 8, 2026 at 10:52 PM
🛡️ Silent Ransom Group Uses Fake IT Support Calls to Pressure Law Firms

Silent Ransom Group is targeting U.S. law firms and professional services organizations with fake IT support calls, remote access tools and rapid data-theft extortion.

#Cybersecurity #ThreatIntel

Link card below.
Silent Ransom Group Uses Fake IT Support Calls to Pressure Law Firms
Silent Ransom Group is targeting U.S. law firms and professional services organizations with fake IT support calls, remote access tools and rapid data-theft extortion. Mandiant links the activity to UNC3753, Luna Moth
stechtimes.com
June 8, 2026 at 12:34 PM
Luna Moth's fake IT callers now show up in person - badge in, back up your files, walk out with everything. https://intel.threadlinqs.com/threat/TL-2026-2127 #ThreatIntel #LockBit #AnyDesk #Bomgar
August 24, 2026 at 2:49 PM
🚨 UNC3753 is targeting US law firms using vishing and RMM tools for data extortion.

In instances linked to UNC3753, individuals posing as IT technicians attempted direct data theft using physical, in-person access.

Read more & get IOCs ➔ goo.gle/49HfT8g
June 5, 2026 at 3:37 PM
UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign
thehackernews.com/2026/06/unc3...
UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign
UNC3753 hit dozens of U.S. firms in Jan-May 2026 using vishing and RMM tools, driving rapid data theft extortion.
thehackernews.com
June 8, 2026 at 9:46 PM
FBI Warns of Luna Moth Ransomware Attacks Targeting U.S. Law Firms #CyberAttacks #Extortion #FBI
FBI Warns of Luna Moth Ransomware Attacks Targeting U.S. Law Firms
 The FBI said that over the last two years, an extortion group known as the Silent Ransom Group has targeted U.S. law firms through callback phishing and social engineering tactics.  This threat outfit, also known as Luna Moth, Chatty Spider, and UNC3753, has been active since 2022. It was also responsible for BazarCall campaigns, which provided initial access to corporate networks for Ryuk and Conti ransomware assaults. Following Conti's shutdown in March 2022, the threat actors broke away from the cybercrime syndicate and created their own operation known as the Silent Ransom Group. In recent attacks, SRG mimics the targets' IT help via email, bogus websites, and phone conversations, gaining access to their networks via social engineering tactics. This extortion group does not encrypt victims' systems and is infamous for demanding ransoms in order to keep sensitive information stolen from hacked devices from being leaked online.  "SRG will then direct the employee to join a remote access session, either through an email sent to them, or navigating to a web page. Once the employee grants access to their device, they are told that work needs to be done overnight," the FBI stated in a private industry notification. "Once in the victim's device, a typical SRG attack involves minimal privilege escalation and quickly pivots to data exfiltration conducted through 'WinSCP' (Windows Secure Copy) or a hidden or renamed version of 'Rclone.'”  After acquiring the victims' data, they use ransom emails to blackmail them, threatening to sell or publish the information. They frequently call employees of breached organisations and force them into ransom negotiations. While they have a dedicated website for disclosing their victims' data, the FBI claims the extortion ring does not always followup on its data leak promises.  To guard against these attacks, the FBI recommends adopting strong passwords, activating two-factor authentication for all employees, performing regular data backups, and teaching personnel on recognising phishing efforts. The FBI's warning follows a recent EclecticIQ report detailing SRG attacks targeting legal and financial institutions in the United States, with attackers observed registering domains to "impersonate IT helpdesk or support portals for major U.S. law firms and financial services firms, using typosquatted patterns.” A recent EclecticIQ report about SRG attacks against American legal and financial institutions revealed that the attackers were registering domains to "impersonate IT helpdesk or support portals for major U.S. law firms and financial services firms, using typosquatted patterns." The FBI issued the warning in response to this information.  Malicious emails with fake helpdesk numbers are being sent to victims, prompting them to call in order to fix a variety of non-existent issues. On the other hand, Luna Moth operators would try to deceive employees of targeted firms into installing remote monitoring & management (RMM) software via phoney IT help desk websites by posing as IT staff. Once the RMM tool is installed and started, the threat actors have direct keyboard access, allowing them to search for valuable documents on compromised devices and shared drivers, which will then be exfiltrated via Rclone (cloud syncing) or WinSCP (SFTP). According to EclecticIQ, the Silent Ransom Group sends ransom demands ranging from one to eight million USD, depending on the size of the hacked company.
dlvr.it
June 14, 2025 at 4:23 PM
FBI Warns of Silent Ransom Group Using Phishing and Vishing to Target U.S. Law Firms #AdvancedSocialEngineering #CyberAttacks #cybercriminalgroup
FBI Warns of Silent Ransom Group Using Phishing and Vishing to Target U.S. Law Firms
 The FBI has issued a warning about a sophisticated cybercriminal group known as the Silent Ransom Group (SRG), also referred to by aliases like Luna Moth, Chatty Spider, and UNC3753. This group has been actively targeting U.S.-based law firms and related organizations through advanced phishing techniques and social engineering scams. The group, which has been operational since 2022, is known for using deceptive communication methods to gain unauthorized access to corporate systems and extract sensitive legal data for ransom demands. In the past, SRG’s activities spanned across industries such as healthcare and insurance.  However, since the spring of 2023, its focus has shifted to legal entities, likely because of the highly confidential nature of the data managed by law firms. The group commonly uses a method called callback phishing, also known as reverse vishing. In this approach, victims receive emails that appear to originate from reputable companies and warn them of small charges for fake subscriptions. The emails prompt users to call a phone number to cancel the subscription. During these calls, victims are instructed to download remote access software under the guise of resolving the issue. Once the software is installed, SRG gains control of the victim’s device, searches for valuable data, and uses it to demand ransom.   In March 2025, SRG has adapted their strategy to include voice phishing or vishing. In this new approach, the attackers call employees directly, posing as internal IT staff. These fraudulent callers attempt to convince their targets to join remote access sessions, often under the pretext of performing necessary overnight maintenance. Once inside the system, the attackers move swiftly to locate and exfiltrate data using tools like WinSCP or a disguised version of Rclone. Notably, SRG does not prioritize escalating privileges, instead focusing on immediate data theft. The FBI noted that these voice phishing methods have already resulted in multiple successful breaches.  SRG reportedly continues to apply pressure during ransom negotiations by making follow-up calls to victim organizations. While the group does maintain a public site for releasing stolen data, its use of this platform is inconsistent, and it does not always follow through on threats to leak information. A significant concern surrounding these attacks is the difficulty in detection. SRG uses legitimate system management and remote access tools, which are often overlooked by traditional antivirus software. The FBI advises organizations to remain vigilant, particularly if there are unexplained downloads of programs such as AnyDesk, Zoho Assist, or Splashtop, or if staff receive unexpected calls from alleged IT personnel.  In response, the FBI urges companies to bolster cybersecurity training, establish clear protocols for authenticating internal IT requests, and enforce two-factor authentication across all employee accounts. Victims of SRG attacks are encouraged to share any information that might assist in ongoing investigations, including ransom communications, caller details, and cryptocurrency wallet data.
dlvr.it
June 4, 2025 at 12:52 PM
UNC3753 blended vishing and physical intrusions to breach U.S. firms in legal, financial, and professional services. New Mandiant analysis reveals how extortion groups are…

https://thehackernews.com/2026/06/unc3753-used-vishing-and-physical.html

#cybersecurity #infosec
June 9, 2026 at 7:30 AM
Silent Ransom Group is using DNS fast flux on infected devices to hide attacks while running vishing and social engineering campaigns against law firms and other sensitive sectors for data theft and extortion. #SilentRansomGroup #FastFlux #Vishing
Silent Ransom Group Uses DNS Fast Flux in Attacks
Silent Ransom Group (SRG), also tracked as Chatty Spider, Luna Moth, and UNC3753, is using fast flux infrastructure built on infected devices to conceal its operations while conducting vishing and social engineering attacks. The group targets law firms and other sensitive industries for data theft and extortion, with its activity linked...
www.hendryadrian.com
June 8, 2026 at 12:00 PM