Silent Ransom Group Targeting Law Firms


The cyber threat actor Silent Ransom Group (SRG), also known as Luna Moth, Chatty Spider, and UNC3753, is targeting law firms using information technology (IT) themed social engineering calls, and callback phishing emails, to gain remote access to systems or devices and steal sensitive data to extort the victims.

While SRG has historically victimized companies in many sectors, starting Spring 2023, the group has consistently targeted US-based law firms, likely due to the highly sensitive nature of legal industry data. *SRG targets other sectors as well, to include companies in the medical industry and insurance industry. However, most of SRG’s victims are law firms or companies with similar naming conventions.

Read more…
Source: U.S. Federal Bureau of Investigation Cyber Division


Sign up for our Newsletter
The latest news and insights delivered right to your inbox.


Related:

  • Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

    August 3, 2026

    This article analyzes new attack classes against passwordless authentication, focusing on Google’s synced passkey ecosystem and the Cloud Authenticator used by desktop clients. The attacks demonstrate how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to take over passkey-protected accounts. Palo Alto Unit 42 shows how an attacker can authenticate ...

  • INTERPOL report finds AI linked to more than half of cybercrime in Africa

    August 3, 2026

    Artificial intelligence is enabling 55 per cent of reported cybercrimes across Africa making attacks faster, more scalable, and increasingly difficult for victims and platforms to detect, according to INTERPOL’s African Cyberthreat Assessment Report 2026. With more than 1.1 billion mobile subscribers recorded in 2025, Africa’s digital transformation is expanding rapidly. However, cybercrime legislation is fragmented and AI readiness ...

  • Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

    July 31, 2026

    Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, conducting widespread but targeted traffic manipulation attacks involving hospitality sector networks served by captive portals worldwide. Despite some tactic, technique, and procedure (TTP) similarities to the Forest Blizzard DNS hijacking operation that we publicly disclosed in April 2026, we attribute this campaign, ...

  • Network Anomaly Detection in KATA

    July 31, 2026

    Once the attacker has breached the corporate network, subsequent stages of the attack often involve leveraging standard domain infrastructure protocols: using Kerberos, running DNS queries, accessing internal services, opening network shares, and other common networking actions. Because this activity is virtually indistinguishable from legitimate network traffic, it is extremely difficult to detect it with traditional ...

  • Toy Ghouls’ new toy: the GenieLocker ransomware

    July 30, 2026

    The new GenieLocker ransomware family has been active since March 2026. It has been used in attacks against organizations in the Russian Federation, primarily in the manufacturing sector, and attributed to the Toy Ghouls group by open-source intelligence (link in Russian). The Toy Ghouls, also known as Bearlyfy, Labubu and Laboo.boo, is a financially motivated extortion group, which ...

  • Durov’s bank accounts frozen after terrorist tag applied

    July 30, 2026

    Telegram co-founder Pavel Durov will not be able to access his bank accounts in Russia after placement on the list of terrorists by financial watchdog Rosfinmonitoring earlier on Thursday, lawyer Dmitry Agranovsky told TASS. Since 2022, Russia has recorded 153,000 crimes committed using Telegram, including the organization of a terrorist attack at the Crocus City Hall, ...