#unc3753
Luna Moth's fake IT callers now show up in person - badge in, back up your files, walk out with everything. https://intel.threadlinqs.com/threat/TL-2026-2127 #ThreatIntel #LockBit #AnyDesk #Bomgar
August 24, 2026 at 2:49 PM
UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data
UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data
A sophisticated cybercriminal group has been quietly targeting law firms and professional services organizations across the United States since the beginning of 2026. The campaign is financially motivated and relies heavily on deception rather than technical exploits. Victims are manipulated into handing over access to their own systems, and by the time they realize what happened, their most sensitive data is already gone. The threat cluster behind these attacks, known as UNC3753, has also been tracked under the names “Luna Moth,” “Chatty Spider,” and “Silent Ransom Group.” The group has been active since at least March 2022 and has a long history of pivoting its tactics to stay effective. From January through May 2026, dozens of organizations in the legal, financial, and professional services sectors were targeted in what appears to be one of the group’s most active and damaging periods yet. Analysts from Google Cloud identified and documented this campaign in detail. According to Google Cloud report shared with Cyber Security News (CSN), Google’s Threat Intelligence Group noted that the entire attack sequence, from the first phone call to completed data theft, often happened within a single business day. In some cases, the data was staged and stolen in under an hour. The group begins each attack by sending a benign-looking invoice-themed email from a consumer email account. The message contains no malicious links or attachments. Its only purpose is to put the target on edge so they are more likely to engage when the threat actors call shortly after, posing as internal IT helpdesk staff. UNC3753 attack lifecycle (Source – Google Cloud) Once on the phone, the attackers convince the target to join a screen-sharing session and download remote monitoring and management tools . After gaining control, the attackers search corporate file systems for high-value documents including legal agreements, tax forms, Social Security numbers, and financial records. They then upload the stolen files to cloud accounts they control. Shortly after exiting the environment, the group sends aggressive extortion emails demanding a response within three days or threatening to notify employees, clients, and journalists about the breach. UNC3753 Uses Screen-Sharing Sessions and RMM Tools Once a victim is on a call with the attacker, they are directed to launch a screen-sharing session through tools like Zoom, Microsoft Teams, or Quick Assist. In one documented case, an attacker held five separate calls with the same person over three days. From there, the group pushes the target to install commercial remote management software such as AnyDesk, Bomgar, or Zoho Assist, giving the attackers persistent access to the machine. To avoid leaving traces, the group uses privnote.com, a self-destructing message service, to send download links and commands. LEAKEDDATA DLS (Source – Google Cloud) Once inside a virtual desktop environment, attackers crawl network drives, search document management platforms like iManage using specific keywords, and stage the results in the user’s Downloads folder. Files are then uploaded through WinSCP, Rclone, or directly through the victim’s own web browser into attacker-controlled cloud storage accounts. In one particularly aggressive incident, the group exfiltrated 1.7 gigabytes from a target’s OneDrive folder to an external account, then pivoted to a virtual desktop session and pulled an additional 14.4 gigabytes using WinSCP. The stolen data was later threatened to be published on a data leak site called LEAKEDDATA if the victim refused to pay. Physical Intrusions Mark a Dangerous Escalation Beyond digital attacks, there are instances where individuals posing as IT technicians physically entered corporate offices to steal data using USB drives. According to an FBI Cyber FLASH Alert cited in the report, if remote social engineering fails, the group sends a person on-site who claims to need physical access to address a security issue. This physical escalation is particularly alarming because most office environments rely solely on basic administrative checks to control entry. Google’s Threat Intelligence Group recommends that organizations conduct targeted awareness training around these specific tactics. Firms should also enforce strict physical access policies, requiring photo identification and escorted entry for all external technical visitors. On the digital side, only corporate-owned devices should be permitted to access virtual desktops or VPNs , and unauthorized remote management tools should be blocked outright. Real-time alerts should be configured in document management platforms to flag bulk file searches and mass downloads. Indicators of Compromise (IoCs):- Type Indicator Description IPv4 Address 192.236.147.131 Actor-controlled infrastructure IPv4 Address 192.236.147.138 Actor-controlled infrastructure IPv4 Address 193.141.60.212 Actor-controlled infrastructure IPv4 Address 192.236.154.158 Actor-controlled infrastructure IPv4 Address 192.236.146.173 Actor-controlled infrastructure IPv4 Address 174.169.162.62 Actor-controlled infrastructure IPv4 Address 64.94.84.97 Actor-controlled infrastructure Domain Pattern <organization>-itdesk[.]com Phishing/vishing support domain Domain Pattern <organization>-it[.]com Phishing/vishing support domain Domain Pattern <organization>-helpdesk[.]com Phishing/vishing support domain Data Leak Site hxxps[:]//business-data-leaks[.]com UNC3753 victim disclosure platform Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in Google . The post UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data appeared first on Cyber Security News .
cybersecuritynews.com
June 17, 2026 at 2:02 AM
UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data A sophisticated cybercriminal group has been quietly targeting law firms and professional services organization...

#cyber #security #news #Threats #cyber #security #Cyber #Security #News

Origin | Interest | Match
June 17, 2026 at 5:01 AM
UNC3753 フィッシング詐欺キャンペーンが米国の法律事務所を標的に恐喝行為

UNC3753 Vishing Campaign Targets US Law Firms for Extortion #DailyCyberSecurity (Jun 15)

securityonline.info/unc3753-vish...
UNC3753 Vishing Campaign Targets US Law Firms for Extortion
Mandiant details the UNC3753 vishing campaign targeting US law firms with fake IT calls, RMM abuse, and rapid data theft extortion.
securityonline.info
June 16, 2026 at 11:30 PM
Silent Ransom Group、ボイスフィッシングとデータ窃取恐喝で米国法律事務所を標的に

UNC3753(Luna Moth、Chatty Spider、Silent Ransom Groupとも呼ばれる)による集中的なデータ窃取・恐喝キャンペーンが、米国の専門サービス、法律、金融サービス企業の数十社を標的にしています。 このグループの特徴は、迅速かつ人間中心の侵害手法にあります。ボイスフィッシング(ビッ...
Silent Ransom Group、ボイスフィッシングとデータ窃取恐喝で米国法律事務所を標的に
UNC3753(Luna Moth、Chatty Spider、Silent Ransom Groupとも呼ばれる)による集中的なデータ窃取・恐喝キャンペーンが、米国の専門サービス、法律、金融サービス企業の数十社を標的にしています。 このグループの特徴は、迅速かつ人間中心の侵害手法にあります。ボイスフィッシング(ビッ
blackhatnews.tokyo
June 16, 2026 at 1:36 PM
Feed: "Cyber Security News"
By: Varshini on Tuesday, June 16, 2026
Silent Ransom Group Threatens US Law Firms With LEAKEDDATA Data Leak Site
A financially motivated threat actor known as UNC3753 is aggressively targeting legal, professional, and financial services across the
cyberpress.org
June 16, 2026 at 11:22 AM
Silent Ransom Group、LEAKEDDATAデータ流出サイトで米国の法律事務所を脅迫

「UNC3753」として知られる金銭的動機を持つ脅威アクターが、米国全土の法律事務所、専門サービス企業、金融機関を積極的に標的にしています。 2026年1月から5月にかけて活動するこのグループは、Silent Ransom Group、Luna Moth、Chatty Spiderとも呼ばれており、従来のランサムウェ
Silent Ransom Group、LEAKEDDATAデータ流出サイトで米国の法律事務所を脅迫
「UNC3753」として知られる金銭的動機を持つ脅威アクターが、米国全土の法律事務所、専門サービス企業、金融機関を積極的に標的にしています。 2026年1月から5月にかけて活動するこのグループは、Silent Ransom Group、Luna Moth、Chatty Spiderとも呼ばれており、従来のランサムウェ
blackhatnews.tokyo
June 16, 2026 at 10:19 AM
Hunting UNC3753-Style Helpdesk Domains Targeting U.S. Law Firms -
https://t.co/YyUEgnz2B1

— from @craiu (https://x.com/craiu/status/2065086636036083883)
Hunting UNC3753-Style Helpdesk Domains Targeting U.S. Law Firms
t.co
June 11, 2026 at 3:17 PM
Cybersecurity alert: UNC3753, linked to a fraud-driven data extortion campaign, targeted dozens of US orgs in professional, legal & financial sectors (Jan-May 2026). #CyberSecurity
UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign
UNC3753 hit dozens of U.S. firms in Jan-May 2026 using vishing and RMM tools, driving rapid data theft extortion.
thehackernews.com
June 9, 2026 at 7:29 PM
UNC3753 Targets U.S. Firms with Vishing and Physical Intrusions for Data Theft and Extortion Link: thedailytechfeed.com/unc3753-targ...
June 9, 2026 at 4:10 PM
UNC3753 targets U.S. law firms with rapid vishing attacks, exploiting trust to steal sensitive data. Firms must bolster defenses against these sophisticated threats. #CyberSecurity #DataBreach #LawFirms Link: thedailytechfeed.com/unc3753-targ...
June 9, 2026 at 2:07 PM
UNC3753 walks into offices posing as IT contractors, calls employees with vishing pretexts, and exfiltrates data in hours using legitimate tools under legitimate user sessions. Your technical controls can't stop what they never see coming. #infosec #cybersecurity
UNC3753 Uses Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign
UNC3753 walks into offices posing as IT contractors, calls employees with vishing pretexts, and exfiltrates data in hours using legitimate tools under legitimate user sessions. Your technical controls can't stop what they never see coming. #infosec #cybersecurity
captechgroup.com
June 9, 2026 at 12:40 PM
UNC3753 attacking US Law Firms using Vishing and RMM Tools to exfiltrate Data:

cybersecuritynews.com/unc3753-atta...
June 9, 2026 at 8:59 AM
UNC3753 blended vishing and physical intrusions to breach U.S. firms in legal, financial, and professional services. New Mandiant analysis reveals how extortion groups are…

https://thehackernews.com/2026/06/unc3753-used-vishing-and-physical.html

#cybersecurity #infosec
June 9, 2026 at 7:30 AM
UNC3753 Escalates: From Vishing Calls to Physical Office Intrusions at US Legal and Financial Firms

UNC3753 phones staff posing as IT, hijacks screen sessions, steals sensitive legal files, and now sends operatives physically into offices to plug in USB drives. Google Mandiant an…
#hackernews #news
UNC3753 Escalates: From Vishing Calls to Physical Office Intrusions at US Legal and Financial Firms
UNC3753 phones staff posing as IT, hijacks screen sessions, steals sensitive legal files, and now sends operatives physically into offices to plug in USB drives. Google Mandiant and the Google Threat Intelligence Group published a detailed report documenting an active extortion campaign carried out by the cybercrime group UNC3753 (aka Luna Moth, Chatty Spider, and […]
securityaffairs.com
June 9, 2026 at 1:37 AM
UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign

Cybersecurity researchers have disclosed details of a financially motivated data theft extortion campaign that has targeted dozens of organizations across professional, legal, and financial service…
#hackernews #news
UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign
Cybersecurity researchers have disclosed details of a financially motivated data theft extortion campaign that has targeted dozens of organizations across professional, legal, and financial services in the U.S. between January and May 2026. The activity has been attributed by Google Mandiant and Google Threat Intelligence Group (GTIG) to a threat actor dubbed UNC3753, which is also known as
thehackernews.com
June 8, 2026 at 10:52 PM
UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign
thehackernews.com/2026/06/unc3...
UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign
UNC3753 hit dozens of U.S. firms in Jan-May 2026 using vishing and RMM tools, driving rapid data theft extortion.
thehackernews.com
June 8, 2026 at 9:46 PM
🚩 UNC3753 Targets US Law Firms With Vishing, RMM Tools, Data Theft, and Physical Intrusion Attempts UNC3753 Targets US Law Firms With Vishing, RMM Tools, Data Theft, and Physical Intrusion Attem...

#TIGR #cybercriminal #malware #phishing

Origin | Interest | Match
Awakari App
awakari.com
June 8, 2026 at 9:32 PM
UNC3753 Attacking US Law Firms Using Vishing and RMM Tools to Exfiltrate Data
UNC3753 Attacking US Law Firms Using Vishing and RMM Tools to Exfiltrate Data
A sophisticated cybercriminal group known as UNC3753 has been running an aggressive campaign against US law firms since early 2026, using phone calls, screen-sharing tricks, and remote monitoring software to break into corporate systems and steal sensitive files. The group is also tracked as Luna Moth, Chatty Spider, and Silent Ransom Group, and has been active since at least March 2022 . Their latest wave ran from January through May 2026 and hit dozens of organizations across legal, professional, and financial services sectors. What makes this campaign alarming is how fast it moves. In many cases, attackers went from the first phone call to actual data theft within a single business day. In some incidents, searching, staging, and exfiltrating files was completed in under an hour. The group does not rely on traditional malware but targets people directly through convincing voice calls. Analysts at Google Cloud said in a report shared with Cyber Security News (CSN) that UNC3753 starts attacks with simple, invoice-themed emails sent from consumer accounts. These messages carry no links or attachments. Their only purpose is to plant concern in the recipient’s mind, making them more likely to answer a follow-up call from someone posing as IT helpdesk staff. Law firms hold highly sensitive information including merger plans, client files, trade secrets, and regulatory reports. Attackers know that firms facing reputational pressure may choose to pay quietly rather than risk public exposure. That calculation drives the entire extortion model. The extortion phase begins almost immediately after theft . Within 30 minutes of exiting a victim’s environment, the group sends a threatening email demanding a response within three days. If ignored, they threaten to contact employees, clients, and the media, and publish stolen files on a data leak site called LEAKEDDATA. UNC3753 Attacking US Law Firms The group’s entry method relies on impersonating corporate IT support staff. Attackers look up publicly listed employee details on company websites, then call those individuals directly. During the call, they claim to address a security issue or assist with a data migration project, building trust before directing the victim into a screen-sharing session. Once screen sharing is active, the attacker guides the victim into downloading remote access tools. UNC3753 has used AnyDesk, Bomgar, Zoho Assist, and a SuperOps RMM agent in separate engagements. To avoid leaving traces, they deliver installation links through Privnote, a self-destructing text tool that erases messages once read. In several cases, attackers accessed corporate virtual desktop environments through BYOD laptops using Windows 365 or Citrix clients. UNC3753 attack lifecycle (Source – Google Cloud) From there, they searched systems like iManage for tax records, Social Security numbers, and legal agreements, then staged files in the Downloads folder before exfiltrating. Organizations should train staff to verify IT calls independently, restrict remote access tool installation, and enforce MFA on document repositories. Data Exfiltration and Physical Intrusion Once files are staged, UNC3753 moves them through several methods. They have used portable WinSCP and Rclone for bulk transfers, or logged directly into cloud storage within the victim’s browser. In one incident, the group moved 1.7 gigabytes to a Google Drive account before pivoting to a VDI session and exfiltrating an additional 14.4 gigabytes using WinSCP. Beyond digital attacks, individuals tied to UNC3753 have physically entered corporate offices posing as IT technicians, a tactic corroborated by an FBI Cyber FLASH Alert. LEAKEDDATA DLS (Source – Google Cloud) These actors claim to image devices and copy data to USB drives before leaving. Disabling USB storage across all endpoints and BYOD systems is a critical control to block this physical threat. Organizations should monitor SSH traffic and outbound transfers for unusual spikes, and configure real-time alerts in document platforms for mass downloads. Phishing domains used by this group follow patterns like organization-itdesk.com and organization-helpdesk.com, which can be blocked at the DNS level. Physical visitor verification, including ID logging and mandatory escort of technical personnel, must be enforced without exception. Indicators of Compromise (IoCs):- Type Indicator Description IPv4 Address 192.236.147.131 UNC3753 actor-controlled IP  IPv4 Address 192.236.147.138 UNC3753 actor-controlled IP  IPv4 Address 193.141.60.212 UNC3753 actor-controlled IP  IPv4 Address 192.236.154.158 UNC3753 actor-controlled IP  IPv4 Address 192.236.146.173 UNC3753 actor-controlled IP  IPv4 Address 174.169.162.62 UNC3753 actor-controlled IP  IPv4 Address 64.94.84.97 UNC3753 actor-controlled IP  Domain Pattern <organization>-itdesk[.]com Vishing/phishing infrastructure domain pattern  Domain Pattern <organization>-it[.]com Vishing/phishing infrastructure domain pattern  Domain Pattern <organization>-helpdesk[.]com Vishing/phishing infrastructure domain pattern  Data Leak Site hxxps[:]//business-data-leaks[.]com UNC3753 victim disclosure platform Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in Google . The post UNC3753 Attacking US Law Firms Using Vishing and RMM Tools to Exfiltrate Data appeared first on Cyber Security News .
cybersecuritynews.com
June 8, 2026 at 3:47 PM