news.mlab.sh
Back to the feed
threat-intel

UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign

High
Summary

UNC3753, also known as Chatty Spider and the Silent Ransom Group, is a threat actor engaged in a financially motivated data theft and extortion campaign targeting organizations in the U.S. between January and May 2026. The group utilizes vishing and social engineering tactics, including impersonating IT support, to gain remote access to systems, exfiltrate sensitive data like legal agreements and PII, and then demands ransom. This activity shares tactical overlaps with UNC2686 and is linked to the now-defunct Conti ransomware gang.

UNC3753’s campaign involves a multi-stage approach, beginning with deceptive vishing calls posing as IT support to convince victims to initiate screen-sharing sessions. Once access is gained, the attackers leverage remote monitoring and management (RMM) utilities to steal data directly or manipulate victims into performing data exfiltration. The group has demonstrated an escalation in tactics, including physical intrusions where attackers pose as IT technicians to steal data via USB media. Google Mandiant has identified overlaps with UNC2686, a previously known BazarCall-style campaign group, and links the operation to the Conti ransomware gang’s early iterations. The group’s focus has shifted towards extortion-only operations since 2022, leveraging data leaks to pressure victims into paying. The targeting of legal services firms is highlighted due to their concentration of sensitive client data.

Read the full article at The Hacker News