Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
OpenAI Expands GPT-3.5 Access With Unlimited Chats for All Users
August 7, 2026
SilverFox Hijacks Drivers to Disable Security Tools
August 7, 2026
Critical Rockwell Automation Flaw Exposes Water Systems to Cyberattacks
August 6, 2026
Home/Threats/Silent Ransom Group Targets Law Firms via IT Support Impersonation
Threats

Silent Ransom Group Targets Law Firms via IT Support Impersonation

Key Takeaways The Silent Ransom Group (SRG) is actively targeting U.S. law firms using sophisticated social engineering. SRG impersonates IT support staff, both remotely and in-person, to gain...

David kimber
David kimber
May 28, 2026 4 Min Read
61 0

Key Takeaways

  • The Silent Ransom Group (SRG) is actively targeting U.S. law firms using sophisticated social engineering.
  • SRG impersonates IT support staff, both remotely and in-person, to gain unauthorized access.
  • Unlike traditional ransomware, SRG focuses on data exfiltration and then threatens public release or sale of sensitive information.
  • The group employs legitimate remote access tools and data transfer utilities, making detection more challenging.
  • The FBI has issued warnings and mitigation advice for organizations to defend against these tactics.

Silent Ransom Group Employs Deceptive IT Support Tactics to Breach Law Firms

A highly persistent cybercriminal organization, known as the Silent Ransom Group (SRG), is intensifying its attacks on U.S. law firms. This threat actor leverages advanced social engineering techniques, specifically impersonating IT support personnel, to infiltrate networks and steal sensitive data. The group’s unique approach eschews traditional ransomware encryption in favor of data exfiltration and subsequent extortion, as detailed in a recent report.

Table Of Content

  • Key Takeaways
  • Silent Ransom Group Employs Deceptive IT Support Tactics to Breach Law Firms
  • Extortion Without Encryption: A New Ransomware Paradigm
  • Ingenious Infiltration Methods
  • What You Should Do
  • Indicators of Compromise (IoCs):-

Operating since at least 2022, SRG is also identified by aliases such as Luna Moth, Chatty Spider, and UNC3753. While their campaigns have spanned various sectors including insurance, finance, and healthcare, law firms have emerged as a consistent primary target since Spring 2023. Their modus operandi is effective: establish trust with employees, gain internal network access, pilfer confidential data, and then demand payment to prevent the information from being publicly exposed.

The Federal Bureau of Investigation (FBI) recently shared insights with Cyber Security News (CSN), indicating that SRG has evolved its tactics to become significantly harder to detect. Instead of deploying malicious software that might trigger antivirus alerts, they now utilize legitimate remote access tools. This strategic shift allows their activities to blend in with normal network operations, complicating identification and mitigation efforts.

Extortion Without Encryption: A New Ransomware Paradigm

What distinguishes SRG from many other ransomware groups is its complete avoidance of data encryption. Victims do not encounter locked systems, desktop ransom notes, or sudden operational shutdowns. Instead, the attackers covertly extract sensitive files and then threaten to sell or publicly release the stolen data unless a ransom is paid. For law firms, which handle highly confidential client information, this threat alone often compels compliance.

The group’s extortion tactics extend beyond initial ransom emails. SRG actors are known to directly contact employees and clients of victim organizations, applying significant pressure to ensure payment. If a ransom demand is not met, the stolen data is published on the group’s public leak site, business-data-leaks[.]com, making it accessible to anyone online.

Ingenious Infiltration Methods

As of Spring 2026, SRG has refined its infiltration strategy to focus on IT department impersonation. Attackers initiate contact with employees either through direct phone calls or phishing emails, urging them to reach out to what appears to be their organization’s internal IT support. Once an employee is on the phone, the attacker attempts to persuade them to grant immediate remote desktop access.

Should remote access attempts fail, SRG is prepared to escalate. The group has been observed deploying individuals to victim locations, where they pose as legitimate IT technicians. These imposters claim they need to image the device or create a backup file, citing a recent phishing threat as justification. This pretext provides them with an opportunity to physically connect a USB drive or external hard drive to the victim’s computer.

Upon gaining access, the attackers move swiftly to exfiltrate data. They employ tools such as WinSCP or a concealed version of Rclone to transfer information from the network to cloud storage or remove it physically on a drive. Every step of this operation is meticulously planned to remain undetected while maximizing the volume of valuable data extracted.

What You Should Do

  • Verify Identity: Establish strict protocols for verifying the identity of any individual claiming to be IT support, especially before granting system access. This includes mandatory ID checks for in-person requests.
  • Define Communication Policies: Implement and communicate clear internal policies regarding how legitimate IT staff will contact employees for support, enabling employees to recognize suspicious interactions.
  • Restrict Remote Access: Block Port 22 where feasible and disable remote access permissions on systems that store or process sensitive data.
  • Mandate Phishing-Resistant MFA: Deploy and enforce phishing-resistant multi-factor authentication (MFA) across all services and applications.
  • Conduct Regular Security Awareness Training: Provide ongoing training to all staff on identifying and reporting social engineering attempts, including phishing emails and suspicious phone calls.
  • Implement Robust Data Backup Strategies: Maintain regular and verified data backups, stored securely and offline, to minimize the impact of data exfiltration.
  • Monitor for Unauthorized Tools: Watch for the unauthorized download or presence of remote access tools (e.g., Zoho Assist, Quick Assist, AnyDesk, RustDesk, Syncro, Splashtop, Atera) and data transfer utilities (e.g., WinSCP, Rclone).

Indicators of Compromise (IoCs):-

Type Indicator Description
Domain business-data-leaks[.]com SRG public-facing leak site used to post stolen victim data
Tool WinSCP (Windows Secure Copy) Used by SRG actors to exfiltrate data to external IP addresses
Tool Rclone (hidden or renamed version) Used by SRG for covert data exfiltration to cloud or remote servers <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/ac440c06-440f-45ce-b9e7-43443df4344a/Silent-Ransom-Group-Targets-Law-Firms-With-IT-Support-Impersonation-Attacks.pdf?AWSAccessKeyId=ASIA2F3EMEYEYA35AXRP&Signature=RxHPOD1ITEhvhlw7WYTECDiPLfQ%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEN3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCX

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitphishingransomwareSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

SBI Warns Customers of YONO App Deactivation Scam

Next Post

Critical Notepad++ Flaws Let Attackers Run Code

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Best Intrusion Detection & Prevention (IDS/IPS) Tools for 2026
August 6, 2026
Critical WSUS Vulnerability Lets Attackers Compromise Enterprise Endpoints
August 6, 2026
Critical Paperclip Flaws Let Attackers Gain Admin Access
August 6, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us