Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Intel’s $20 Billion Stock Sale Sparks Debate on Chip Supply Chain Security
August 11, 2026
LLM API Vulnerability Exposes AI Model Reasoning, Poses Data Risk
August 11, 2026
Critical SAP Vulnerabilities Allow Code Injection, Memory Corruption
August 11, 2026
Home/Threats/UNC3753 Attackers Steal Legal Data via Screen-Sharing and RMM Tools
Threats

UNC3753 Attackers Steal Legal Data via Screen-Sharing and RMM Tools

Key Takeaways The UNC3753 cybercriminal group is actively targeting U.S. law firms and professional services organizations. Attacks heavily rely on social engineering, manipulating victims into...

Marcus Rodriguez
Marcus Rodriguez
June 17, 2026 4 Min Read
46 0

Key Takeaways

  • The UNC3753 cybercriminal group is actively targeting U.S. law firms and professional services organizations.
  • Attacks heavily rely on social engineering, manipulating victims into granting access via screen-sharing and remote management tools.
  • High-value legal and financial data is exfiltrated, followed by aggressive extortion demands.
  • The group has escalated tactics to include physical intrusions into corporate offices.

Sophisticated UNC3753 Group Targets U.S. Law Firms with Deceptive Tactics

Since early 2026, a highly organized cybercriminal entity identified as UNC3753 has been systematically attacking law firms and professional services organizations across the United States. This financially motivated campaign distinguishes itself by employing sophisticated social engineering techniques, rather than relying on complex technical exploits, to compromise target systems and steal sensitive data.

Table Of Content

  • Key Takeaways
  • Sophisticated UNC3753 Group Targets U.S. Law Firms with Deceptive Tactics
  • Attack Chain: From Phishing to Extortion
  • Leveraging Screen-Sharing and RMM Tools for Persistent Access
  • Physical Intrusions: A Dangerous Escalation
  • What You Should Do

The threat group, also recognized by aliases such as “Luna Moth,” “Chatty Spider,” and “Silent Ransom Group,” has demonstrated consistent activity since at least March 2022. Their operational methods are fluid, constantly adapting to maintain effectiveness. A significant surge in activity was observed between January and May 2026, during which numerous organizations in the legal, financial, and professional services sectors fell victim. Analysts from Google Cloud meticulously documented this surge, highlighting it as one of the group’s most impactful periods to date.

A report by Google Cloud’s Threat Intelligence Group, shared with Cyber Security News (CSN), revealed that the entire attack lifecycle, from the initial contact to the successful exfiltration of data, often concludes within a single business day. In some instances, data was staged and stolen in less than an hour, underscoring the speed and efficiency of UNC3753’s operations.

Attack Chain: From Phishing to Extortion

The attack sequence typically initiates with a seemingly innocuous email, designed to mimic an invoice. Sent from a consumer email account, these messages are devoid of malicious links or attachments. Their primary objective is to create a sense of urgency or concern for the recipient, making them more susceptible to subsequent social engineering. Shortly after, threat actors follow up with a phone call, impersonating internal IT helpdesk personnel.

During these phone calls, the attackers skillfully persuade targets to participate in screen-sharing sessions and download commercial remote monitoring and management (RMM) software. Once remote control is established, UNC3753 actors methodically search corporate file systems for high-value documents, including legal contracts, tax records, Social Security numbers, and financial statements. The pilfered data is then uploaded to cloud storage accounts controlled by the attackers. Following their exit from the compromised environment, the group dispatches aggressive extortion emails, demanding payment within three days under threat of publicizing the breach to employees, clients, and journalists.

Leveraging Screen-Sharing and RMM Tools for Persistent Access

The social engineering phase is critical. Victims are directed to initiate screen-sharing sessions using legitimate platforms like Zoom, Microsoft Teams, or Quick Assist. Google Cloud observed one incident where an attacker engaged in five separate calls with the same individual over three days. Subsequently, victims are coerced into installing commercial remote management software such as AnyDesk, Bomgar, or Zoho Assist, which grants the attackers persistent access to the compromised machine.

To obscure their tracks, UNC3753 utilizes privnote.com, a service that provides self-destructing messages, for transmitting download links and commands. Inside virtual desktop environments, attackers systematically crawl network drives and search document management platforms like iManage using specific keywords. The gathered results are staged in the user’s Downloads folder. Exfiltration is then carried out using tools like WinSCP, Rclone, or directly through the victim’s web browser, transferring files to attacker-controlled cloud storage.

In one particularly aggressive incident, the group exfiltrated 1.7 gigabytes from a target’s OneDrive folder to an external account. They then pivoted to a virtual desktop session, extracting an additional 14.4 gigabytes using WinSCP. The stolen data was later threatened to be published on a data leak site named LEAKEDDATA if the victim failed to comply with their demands.

Physical Intrusions: A Dangerous Escalation

Beyond digital breaches, UNC3753 has demonstrated an alarming escalation in tactics, including instances of physical intrusion. Individuals posing as IT technicians have physically entered corporate offices to steal data using USB drives. An FBI Cyber FLASH Alert, referenced in the Google Cloud report, indicates that if remote social engineering attempts fail, the group resorts to sending an on-site operative who claims to require physical access to address a security issue. This physical component is particularly concerning, as many office environments rely solely on basic administrative checks for entry control.

What You Should Do

  • Conduct Targeted Awareness Training: Educate employees about invoice-themed phishing, imposter calls from “IT helpdesk,” and the dangers of installing unauthorized remote access software or sharing screens.
  • Enforce Strict Physical Access Policies: Implement robust physical security measures requiring photo identification and escorted entry for all external technical visitors.
  • Restrict Device Access: Permit only corporate-owned devices to access virtual desktops or VPNs.
  • Block Unauthorized RMM Tools: Proactively block the installation and use of commercial remote management software not approved by your organization.
  • Implement Real-time Alerts: Configure alerts in document management platforms to detect and flag unusual activity, such as bulk file searches and mass downloads.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitphishingSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

ClickFix Campaign Infects Windows Users With EtherHiding, GULoader

Next Post

OnionDrop Loader Uses gainmsg C2 to Deliver LegionLoader Payloads

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Vulnerability in Emerson Controllers Lets Attackers Spoof Temperatures
August 11, 2026
US SOCs Combat Alert Fatigue: Strategies for Cybersecurity Noise Reduction
August 11, 2026
Critical Windows PnP Vulnerability Lets Attackers Gain SYSTEM Access
August 11, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us