Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Rockwell Automation Flaw Exposes Water Systems to Cyberattacks
August 6, 2026
Vanta Stealer Drains Browser, Crypto, and Gaming Accounts
August 6, 2026
Critical Flaws in Anthropic, Google, OpenAI Coding Agents Allow RCE
August 6, 2026
Home/Threats/UNC3753 Targets US Law Firms With Vishing and RMM Tools to Exfiltrate Data
Threats

UNC3753 Targets US Law Firms With Vishing and RMM Tools to Exfiltrate Data

Key Takeaways A threat group, UNC3753 (also known as Luna Moth, Chatty Spider, and Silent Ransom Group), has been actively targeting US law firms, professional services, and financial organizations...

Sarah simpson
Sarah simpson
June 8, 2026 5 Min Read
49 0

Key Takeaways

  • A threat group, UNC3753 (also known as Luna Moth, Chatty Spider, and Silent Ransom Group), has been actively targeting US law firms, professional services, and financial organizations since at least March 2022.
  • The campaign, observed from January through May 2026, leverages sophisticated vishing (voice phishing) and remote monitoring and management (RMM) tools to rapidly exfiltrate sensitive data.
  • Attackers often move from initial contact to data theft within a single business day, sometimes completing file staging and exfiltration in under an hour.
  • Beyond digital tactics, the group has reportedly engaged in physical intrusions, with operatives posing as IT technicians to access and copy data from devices on-site.
  • The exfiltrated data is then used in a swift extortion scheme, threatening public disclosure on a data leak site named LEAKEDDATA if demands are not met.

A persistent cybercriminal entity identified as UNC3753 has intensified its attacks on US law firms and other professional and financial service organizations, initiating campaigns as early as March 2022. A recent surge in activity, spanning from January to May 2026, saw dozens of organizations fall victim to this highly effective group, which is also tracked under aliases such as Luna Moth, Chatty Spider, and Silent Ransom Group.

Table Of Content

  • Key Takeaways
  • UNC3753 Attack Methodology
  • Data Exfiltration and Physical Intrusion
  • Indicators of Compromise (IoCs)
  • What You Should Do

What distinguishes UNC3753’s operations is their remarkable speed. In numerous incidents, the attackers progressed from initial telephonic contact to significant data exfiltration within a single business day. Some cases even documented the entire process—including data discovery, staging, and transfer—being completed in less than an hour, according to a detailed report shared with Cyber Security News (CSN) by analysts at Google Cloud.

The group predominantly bypasses traditional malware deployment, instead focusing on direct human manipulation through convincing vishing calls. These attacks often begin with innocuous, invoice-themed emails sent from consumer accounts, devoid of malicious links or attachments. Their sole purpose is to create a sense of urgency or concern, priming recipients to respond positively to a subsequent phone call from an individual impersonating an IT helpdesk employee.

Law firms, in particular, are high-value targets due to the highly sensitive information they manage, including client files, merger and acquisition strategies, trade secrets, and regulatory documents. The attackers exploit the reputational risks associated with a data breach, calculating that firms are more likely to comply with extortion demands quietly rather than face public exposure and potential client backlash.

The extortion phase commences almost immediately after data theft. Within 30 minutes of exiting a victim’s network, UNC3753 dispatches a threatening email, demanding a response within three days. Failure to comply is met with threats to contact employees, clients, and media outlets, alongside the imminent publication of stolen files on their dedicated data leak site, LEAKEDDATA.

UNC3753 Attack Methodology

The group’s initial access hinges on sophisticated social engineering. Attackers meticulously research publicly available employee information, such as names and contact details, from company websites. They then cold-call these individuals, posing as internal IT support staff. During these calls, the imposters fabricate scenarios such as urgent security issues or ongoing data migration projects, skillfully building rapport to persuade victims into initiating screen-sharing sessions.

Once screen-sharing is established, the attackers guide victims to download remote access tools. UNC3753 has been observed utilizing various legitimate RMM solutions, including AnyDesk, Bomgar, Zoho Assist, and SuperOps RMM agents, across different engagements. To minimize their digital footprint, installation links for these tools are often delivered via Privnote, a service that automatically deletes messages after they are read.

In several documented incidents, UNC3753 gained access to corporate virtual desktop environments, such as Windows 365 or Citrix clients, often exploiting bring-your-own-device (BYOD) laptops. From these virtual environments, they systematically searched for sensitive documents, including tax records, Social Security numbers, and legal agreements, within platforms like iManage. Discovered files were then staged in the victim’s Downloads folder before being exfiltrated.

Data Exfiltration and Physical Intrusion

For data exfiltration, UNC3753 employs diverse methods. They have been documented using portable versions of WinSCP and Rclone for bulk file transfers. In other instances, attackers directly logged into cloud storage services from within the victim’s compromised browser session. One notable incident involved the exfiltration of 1.7 gigabytes to a Google Drive account, followed by a pivot to a VDI session to transfer an additional 14.4 gigabytes using WinSCP.

Alarmingly, individuals associated with UNC3753 have also resorted to physical intrusion, posing as IT technicians to gain entry into corporate offices. This tactic, corroborated by an FBI Cyber FLASH Alert, involves actors claiming to image devices and copy data to USB drives on-site. This highlights a dual threat model, encompassing both sophisticated digital and audacious physical infiltration.

Indicators of Compromise (IoCs)

Type Indicator Description
IPv4 Address 192.236.147.131 UNC3753 actor-controlled IP
IPv4 Address 192.236.147.138 UNC3753 actor-controlled IP
IPv4 Address 193.141.60.212 UNC3753 actor-controlled IP
IPv4 Address 192.236.154.158 UNC3753 actor-controlled IP
IPv4 Address 192.236.146.173 UNC3753 actor-controlled IP
IPv4 Address 174.169.162.62 UNC3753 actor-controlled IP
IPv4 Address 64.94.84.97 UNC3753 actor-controlled IP
Domain Pattern <organization>-itdesk[.]com Vishing/phishing infrastructure domain pattern
Domain Pattern <organization>-it[.]com Vishing/phishing infrastructure domain pattern
Domain Pattern <organization>-helpdesk[.]com Vishing/phishing infrastructure domain pattern
Data Leak Site hxxps[:]//business-data-leaks[.]com UNC3753 victim disclosure platform

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

What You Should Do

  • Strengthen Employee Training: Conduct regular, comprehensive cybersecurity awareness training, specifically emphasizing verification protocols for unsolicited IT calls and emails. Employees should be instructed to independently verify any IT support requests through established, official channels rather than relying on caller ID or email addresses.
  • Restrict Remote Access Tools: Implement strict policies and technical controls to prevent unauthorized installation of remote access and remote monitoring and management (RMM) software on all corporate and BYOD devices. Whitelist approved applications and monitor for any deviations.
  • Enforce Multi-Factor Authentication (MFA): Mandate MFA for access to all sensitive systems, including email, document repositories (like iManage), virtual desktop environments (Windows 365, Citrix), and cloud storage services.
  • Monitor Network Traffic: Continuously monitor SSH traffic and outbound data transfers for unusual spikes or patterns that could indicate unauthorized data exfiltration. Configure real-time alerts within document management platforms for mass downloads or suspicious file access.
  • Implement DNS Filtering and Blocking: Block known malicious IP addresses and domain patterns, such as <organization>-itdesk[.]com and <organization>-helpdesk[.]com, at the DNS level to prevent employees from inadvertently accessing attacker infrastructure.
  • Disable USB Storage: Implement endpoint security policies to disable or restrict USB storage devices across all corporate and BYOD systems to mitigate the risk of physical data theft.
  • Enhance Physical Security Protocols: Enforce stringent physical visitor verification procedures, including mandatory ID logging and continuous escort for any external technical personnel, to counter physical intrusion attempts.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarephishingSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

WhatsApp Foils Pegasus Spyware Attack by NSO Group

Next Post

Lucid Stealer Targets 18 Browsers, Crypto Wallets, Discord Tokens

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Paperclip Flaws Let Attackers Gain Admin Access
August 6, 2026
Fake Movie Download Exposes Passwords, Payments, Crypto Assets
August 6, 2026
Critical Oracle Solaris CVE-2024-21013 Flaw Lets Attackers Remotely Control Servers
August 6, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us