Analysis
MARKET SIGNAL:

Silent Ransom Group Uses Fake IT Support Calls to Pressure Law Firms

Newsroom brief

Silent Ransom Group is targeting U.S. law firms and professional services organizations with fake IT support calls, remote access tools and rapid data-theft extortion. Mandiant links the activity to UNC3753, Luna Moth and Chatty Spider, while the FBI has warned of related social engineering and in-person theft attempts.

Verified against source materialEdited by SendTech Times Cybersecurity Desk
Silent Ransom Group Uses Fake IT Support Calls to Pressure Law Firms
Image source: BleepingComputer

Fake help desks put law-firm data at the center of the attack

Silent Ransom Group is using fake IT support calls to target U.S. law firms and professional services organizations, with Mandiant warning that data theft can follow within hours of the first contact.

The campaign is significant because the group is not relying on a conventional ransomware detonation.

Its pressure point is the legal sector’s concentration of sensitive client files and the reputational cost of a public data leak.

Mandiant tracks the actor as UNC3753 and also links it to the names Luna Moth and Chatty Spider.

The activity described in the report spans January to May 2026 and includes dozens of organizations across legal, financial and professional services.

The FBI also issued a FLASH advisory last week warning that U.S. law firms were being targeted through social engineering and in-person data theft attempts.

The intrusion starts with a benign-looking email and a voice call

The initial lure is deliberately low on malware indicators.

Attackers send invoice-themed phishing emails from consumer email accounts, but the messages do not carry malicious links or attachments.

Their role is to prepare the victim for a follow-up phone call in which the attacker impersonates corporate IT staff.

That callback model is familiar from BazarCall campaigns previously tied to Ryuk and Conti ransomware operations.

In this campaign, the attacker pushes the employee into a remote support session through Microsoft Teams, Zoom, Quick Assist or Microsoft Terminal Services.

During the session, the attacker steers the employee toward installing legitimate remote administration software.

The named tools include AnyDesk, Zoho Assist, Bomgar and SuperOps, and the installation gives the actor initial access without needing to defeat endpoint defenses through a malicious attachment.

Remote support tools become the path to legal files

Once inside, the group looks for sensitive legal and financial material.

The source lists contracts, tax records, Social Security numbers, merger and acquisition files, document management platforms and cloud storage repositories as targets.

Exfiltration is commonly performed with tools such as WinSCP or Rclone.

Mandiant also found phishing domains that imitate internal IT portals and use naming patterns designed to look like corporate help-desk infrastructure.

The group uses privnote[.]com to pass installation links and commands during support sessions.

Because the service destroys messages, the method can reduce evidence left in browser histories or corporate chat logs.

Extortion moves quickly after the theft

The operational tempo is one of the clearest warnings for law firms.

Mandiant says ransom demands often arrive within 30 minutes after the attackers leave a victim environment.

The letters give the organization a three-day deadline to respond and start negotiations.

If the victim does not engage, the actor threatens to contact employees and external clients directly.

The letters emphasize client trust, regulatory exposure and the possibility that clients could sue over data mishandling.

That pressure is tailored to legal services, where client confidentiality and deal files can be more damaging than downtime.

In-person theft remains an unresolved but connected risk

The FBI advisory adds another route: attackers impersonating IT staff by phone or email may try to visit offices physically to image computers or create backups while stealing files.

Mandiant said forensic evidence is limited, but it views the in-person activity as likely connected to UNC3753 because the targeting, timelines and behavior match.

Silent Ransom Group has been active since at least 2022, after earlier links to the Ryuk and Conti cybercrime ecosystem.

The group later shifted toward standalone data-theft extortion, where stolen information becomes the leverage instead of encrypted systems.

A separate Resecurity report says the gang is also using fast-flux infrastructure and residential IP addresses across multiple regions to protect data-leak platforms.

Defenses focus on verification and remote-access control

The practical response is not limited to email filtering.

Mandiant and the FBI recommend strict verification for IT support interactions, tighter control over remote access tools, MFA enforcement, USB storage restrictions and employee training against voice phishing.

For law firms and professional services organizations, the watchpoint is whether support workflows can prove the caller’s identity before a remote session begins.

The source does not confirm every in-person case as UNC3753, but it does show that the group’s current playbook combines voice-led social engineering, legitimate remote tools, rapid file theft and pressure tactics designed for high-value client data.

Share this article
inXf

Related articles

More
Check Point VPN Exploitation Puts Legacy IKEv1 Access In The Ransomware Spotlight
Cybersecurity

Check Point VPN Exploitation Puts Legacy IKEv1 Access In The Ransomware Spotlight

A critical Check Point VPN flaw, CVE-2026-50751, is being exploited against legacy IKEv1 remote-access configurations, with activity tied in one case to a Qilin ransomware affiliate and a second related VPN issue also disclosed.

AI Coding Push Turns Developers Into a Prime Cybersecurity Target
Cybersecurity

AI Coding Push Turns Developers Into a Prime Cybersecurity Target

A Japanese @IT analysis says attackers are increasingly targeting developers because AI coding tools, OSS, CI/CD pipelines and cloud services concentrate valuable credentials around them. The report highlights vulnerable AI-generated code, fake recruiting approaches, polluted open-source packages and GitHub Actions-style automation attacks. The practical warning is that companies need stronger identity, dependency and workflow controls rather than relying only on individual developer caution.

AI Reprices Cybercrime Risk Around Phishing And Deepfakes
Cybersecurity

AI Reprices Cybercrime Risk Around Phishing And Deepfakes

A Forbes contributor analysis by Dr. Jonathan Reichental, republished by Yahoo Finance, says generative AI is reducing the cost and skill needed for phishing and social-engineering attacks. The piece frames AI cyber risk as an operating-control problem for payment approvals, access requests, employee training, simulations, defensive tools and board-level governance.

Union County Clues Point To $1 Million Kairos Data-Extortion Payment
Cybersecurity

Union County Clues Point To $1 Million Kairos Data-Extortion Payment

A Ransom-ISAC case study says Kairos took about $1 million after stealing files without encrypting systems. Clues point to Union County, Ohio, The public record does not confirm the link or prove the data was deleted.

Smart TV Proxy SDKs Turn Free Apps Into a Hidden AI Scraping Supply Chain
Cybersecurity

Smart TV Proxy SDKs Turn Free Apps Into a Hidden AI Scraping Supply Chain

Bright Data's SDK has been reverse-engineered in research showing how free apps can turn consumer devices, including smart TVs, into residential proxy nodes for web-scraping traffic. The issue matters because AI data harvesting is increasing demand for residential IPs, while consent screens and background network behavior may not be clear to users or IT teams.

NFSP Ransomware Attack Turns Supplier Email Pause Into a Security-Control Test
Cybersecurity

NFSP Ransomware Attack Turns Supplier Email Pause Into a Security-Control Test

The National Federation of Subpostmasters was hit by ransomware after a cPanel-related hosting software bug was exploited. The NFSP was targeted on 30 April, and the Post Office paused some email interactions with the federation while saying branch operations were not affected. The immediate test is whether trusted communications can resume without pushing subpostmasters toward insecure workaround channels.

Keep Reading

More Stories

Latest
BitMEX Wind-Down Ends A Perpetual-Swap Pioneer After 11 YearsCrypto/Web3Jul 23, 2026BitMEX Wind-Down Ends A Perpetual-Swap Pioneer After 11 YearsCoinDesk reported that BitMEX will shut down operations on September 23, 2026, with new registrations halted, user withdrawals urged and remaining contracts set for forced closure before the final deadline.South Korea Tests AI-RAN And 5G For Industrial Robot NetworksTelco & ConnectivityJul 23, 2026South Korea Tests AI-RAN And 5G For Industrial Robot NetworksRCR Wireless reports that South Korea has put KRW17.2 billion ($11.6 million) behind SK Telecom and KT-led AI-RAN trials for shipyards, factories and robot workloads.CXMT Pre-IPO Contract Tests Crypto Price Discovery For China Chip ListingCapital & PolicyJul 23, 2026CXMT Pre-IPO Contract Tests Crypto Price Discovery For China Chip ListingA Hyperliquid contract linked to ChangXin Memory Technologies is pricing the Chinese memory-chip maker far above its planned Shanghai offer before a restricted STAR market debut.Treasury Warning Sends Moonshot Distillation Claim Toward AI SanctionsCapital & PolicyJul 23, 2026Treasury Warning Sends Moonshot Distillation Claim Toward AI SanctionsA U.S. Treasury warning over alleged AI model distillation brings Moonshot’s Kimi K3 release into a policy test for Chinese open-weight models, Nvidia GB300 access and export-control enforcement.Google Keeps TPU Priority On AGI As Cloud Demand Strains CapacityAIJul 23, 2026Google Keeps TPU Priority On AGI As Cloud Demand Strains CapacityAlphabet told investors that its first compute-allocation priority is frontier AGI development, while Google Cloud demand and AI infrastructure spending are pushing the company to use third-party capacity as a bridge.White House Presses PJM Grid Reform As AI Power Demand RisesCloud & Data CentersJul 23, 2026White House Presses PJM Grid Reform As AI Power Demand RisesThe White House warned PJM Interconnection to reform its board governance and stakeholder process as AI data centres and other large loads intensify disputes over grid reliability, electricity prices and infrastructure cost allocation.OpenAI Presence Makes Enterprise AI Agents A Consulting SaleAIJul 22, 2026OpenAI Presence Makes Enterprise AI Agents A Consulting SaleOpenAI’s Presence service is available to eligible enterprise customers through deployed engineers, not as a self-service product, with pricing still scoped individually.Kratos Takedown Leaves Microsoft 365 Session-Theft Risk UnfinishedCybersecurityJul 22, 2026Kratos Takedown Leaves Microsoft 365 Session-Theft Risk UnfinishedGerman and US law enforcement took more than 200 Kratos phishing-kit servers offline, but investigators still tie the service to roughly 1,800 customers and session-theft attacks against Microsoft 365.Augustus Raises $180m For Dollar Rails Across Emerging-Market FintechsFintech & Digital PaymentsJul 22, 2026Augustus Raises $180m For Dollar Rails Across Emerging-Market FintechsAugustus announced a $180 million Series B at a $1 billion valuation, with funding aimed at dollar accounts, payment rails and stablecoin-enabled banking for fintechs and banks across Latin America, Southeast Asia, the Middle East and Africa.China IPv6 Plan Advances Single-Stack Network And Metadata ControlsTelco & ConnectivityJul 22, 2026China IPv6 Plan Advances Single-Stack Network And Metadata ControlsChina is setting 2027 and 2030 IPv6 targets while pushing IPv6+ work that could give carriers more metadata about traffic, raising policy questions for network and cloud buyers outside China.Prysmian Signs $6.29bn Molex Cable Deal For AI Data CentresCloud & Data CentersJul 22, 2026Prysmian Signs $6.29bn Molex Cable Deal For AI Data CentresData Center Dynamics reported that Prysmian’s €5.5 billion Molex agreement includes a €550 million upfront payment and a capacity plan to more than double US fibre output.Spain AI Campus Seeks 300 MW With On-Site Power PlanCloud & Data CentersJul 22, 2026Spain AI Campus Seeks 300 MW With On-Site Power PlanData Center Knowledge reported that EdgeMode, BlackBerry AIF and Mora are seeking regional support for DC MALPICA, a proposed €3 billion ($3.4 billion), 300 MW AI campus whose power model remains partly undisclosed.