Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms


From January through May 2026, Mandiant identified a financially motivated data theft extortion campaign executed by the threat cluster UNC3753 (also tracked as “Luna Moth,” “Chatty Spider,” and “Silent Ransom Group”) targeting dozens of organizations across professional, legal, and financial services in the United States.

UNC3753 leverages voice phishing (vishing) and social engineering deception techniques to achieve remote access into corporate environments. Using pretexts such as data migration or invoice related emails, the threat actors initiate phone conversations posing as IT support and convince targets to host screen-sharing sessions and download remote monitoring and management (RMM) utilities.

Read more…
Source: Mandiant


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • FakeSG enters the ‘FakeUpdates’ arena to deliver NetSupport RAT

    July 19, 2023

    Over 5 years ago, Malwarebytes researchers began tracking a new campaign that they called FakeUpdates (also known as SocGholish) that used compromised websites to trick users into running a fake browser update. Instead, victims would end up infecting their computers with the NetSupport RAT, allowing threat actors to gain remote access and deliver additional payloads. Read more… Source: ...

  • Victims of Cyberattack on File-Transfer Tool Pile Up

    July 19, 2023

    The list of companies hit by a cyberattack on a widely used software tool continues to expand and several victims have filed lawsuits alleging mishandling of data. The continued disclosure of new victims affected by hackers exploiting a vulnerability in MoveIt, a common file-transfer tool from Progress Software, underscores how cyberattacks can ripple through supply chains. ...

  • North Carolina: Kannapolis didn’t alert public when cyberattack knocked out police dispatch

    July 19, 2023

    More than a year ago, a cyberattack knocked out the system used in Kannapolis to dispatch police and firefighters. You wouldn’t know that based on what the city told the public. Read more… Source: Yahoo! News  

  • Many businesses don’t even know they’ve been hit by a security breach

    July 19, 2023

    Many businesses don’t know if they have suffered a data breach, and probably wouldn’t be able to spot such an event at all, due to the ever-expanding threat landscape, and notification fatigue among IT staff, new research has claimed. A report from cybersecurity experts Vectra AI surveying more than 2,000 IT security analysts found that nearly ...

  • Estee Lauder says hacker obtained some data from its systems

    July 19, 2023

    Beauty products maker Estee Lauder said on Tuesday that a hacker had obtained some data from its systems, and the incident was expected to cause disruption to parts of the company’s operations. The firm said it is working to understand the nature and scope of that data that was stolen. Estee Lauder added that it had ...

  • FIN8 Uses Revamped Sardonic Backdoor to Deliver Noberus Ransomware

    July 18, 2023

    Symantec’s Threat Hunter Team, a part of Broadcom, recently observed the Syssphinx (aka FIN8) cyber-crime group deploying a variant of the Sardonic backdoor to deliver the Noberus ransomware. While analysis of the backdoor revealed it to be part of the Sardonic framework previously used by the group, and analyzed in a 2021 report from Bitdefender, it ...