Silent Ransom Group Targets Law Firms via IT Support Impersonation
Key Takeaways The Silent Ransom Group (SRG) is actively targeting U.S. law firms using sophisticated social engineering. SRG impersonates IT support staff, both remotely and in-person, to gain...
Key Takeaways
- The Silent Ransom Group (SRG) is actively targeting U.S. law firms using sophisticated social engineering.
- SRG impersonates IT support staff, both remotely and in-person, to gain unauthorized access.
- Unlike traditional ransomware, SRG focuses on data exfiltration and then threatens public release or sale of sensitive information.
- The group employs legitimate remote access tools and data transfer utilities, making detection more challenging.
- The FBI has issued warnings and mitigation advice for organizations to defend against these tactics.
Silent Ransom Group Employs Deceptive IT Support Tactics to Breach Law Firms
A highly persistent cybercriminal organization, known as the Silent Ransom Group (SRG), is intensifying its attacks on U.S. law firms. This threat actor leverages advanced social engineering techniques, specifically impersonating IT support personnel, to infiltrate networks and steal sensitive data. The group’s unique approach eschews traditional ransomware encryption in favor of data exfiltration and subsequent extortion, as detailed in a recent report.
Table Of Content
Operating since at least 2022, SRG is also identified by aliases such as Luna Moth, Chatty Spider, and UNC3753. While their campaigns have spanned various sectors including insurance, finance, and healthcare, law firms have emerged as a consistent primary target since Spring 2023. Their modus operandi is effective: establish trust with employees, gain internal network access, pilfer confidential data, and then demand payment to prevent the information from being publicly exposed.
The Federal Bureau of Investigation (FBI) recently shared insights with Cyber Security News (CSN), indicating that SRG has evolved its tactics to become significantly harder to detect. Instead of deploying malicious software that might trigger antivirus alerts, they now utilize legitimate remote access tools. This strategic shift allows their activities to blend in with normal network operations, complicating identification and mitigation efforts.
Extortion Without Encryption: A New Ransomware Paradigm
What distinguishes SRG from many other ransomware groups is its complete avoidance of data encryption. Victims do not encounter locked systems, desktop ransom notes, or sudden operational shutdowns. Instead, the attackers covertly extract sensitive files and then threaten to sell or publicly release the stolen data unless a ransom is paid. For law firms, which handle highly confidential client information, this threat alone often compels compliance.
The group’s extortion tactics extend beyond initial ransom emails. SRG actors are known to directly contact employees and clients of victim organizations, applying significant pressure to ensure payment. If a ransom demand is not met, the stolen data is published on the group’s public leak site, business-data-leaks[.]com, making it accessible to anyone online.
Ingenious Infiltration Methods
As of Spring 2026, SRG has refined its infiltration strategy to focus on IT department impersonation. Attackers initiate contact with employees either through direct phone calls or phishing emails, urging them to reach out to what appears to be their organization’s internal IT support. Once an employee is on the phone, the attacker attempts to persuade them to grant immediate remote desktop access.
Should remote access attempts fail, SRG is prepared to escalate. The group has been observed deploying individuals to victim locations, where they pose as legitimate IT technicians. These imposters claim they need to image the device or create a backup file, citing a recent phishing threat as justification. This pretext provides them with an opportunity to physically connect a USB drive or external hard drive to the victim’s computer.
Upon gaining access, the attackers move swiftly to exfiltrate data. They employ tools such as WinSCP or a concealed version of Rclone to transfer information from the network to cloud storage or remove it physically on a drive. Every step of this operation is meticulously planned to remain undetected while maximizing the volume of valuable data extracted.
What You Should Do
- Verify Identity: Establish strict protocols for verifying the identity of any individual claiming to be IT support, especially before granting system access. This includes mandatory ID checks for in-person requests.
- Define Communication Policies: Implement and communicate clear internal policies regarding how legitimate IT staff will contact employees for support, enabling employees to recognize suspicious interactions.
- Restrict Remote Access: Block Port 22 where feasible and disable remote access permissions on systems that store or process sensitive data.
- Mandate Phishing-Resistant MFA: Deploy and enforce phishing-resistant multi-factor authentication (MFA) across all services and applications.
- Conduct Regular Security Awareness Training: Provide ongoing training to all staff on identifying and reporting social engineering attempts, including phishing emails and suspicious phone calls.
- Implement Robust Data Backup Strategies: Maintain regular and verified data backups, stored securely and offline, to minimize the impact of data exfiltration.
- Monitor for Unauthorized Tools: Watch for the unauthorized download or presence of remote access tools (e.g., Zoho Assist, Quick Assist, AnyDesk, RustDesk, Syncro, Splashtop, Atera) and data transfer utilities (e.g., WinSCP, Rclone).



No Comment! Be the first one.