news.mlab.sh
Back to the feed
threat-intel

Silent Ransom Group targets law firms with fake IT support calls

High
Summary

The Silent Ransom Group is aggressively targeting U.S. law firms through sophisticated social engineering attacks, primarily involving fake IT support calls. These attacks begin with phishing emails and escalate to remote access installations, ultimately leading to data theft and extortion demands. The group, tracked as UNC3753, leverages tactics similar to those used in previous BazarCall campaigns, highlighting the ongoing threat to the legal sector.

The Silent Ransom Group is currently engaged in a campaign focused on law firms and professional services organizations, utilizing a multi-stage approach to compromise systems and exfiltrate sensitive data. Initial contact typically occurs via invoice-themed phishing emails, designed to lure victims into returning calls from attackers posing as IT support staff. These calls then lead to the installation of remote access tools like AnyDesk or Zoho Assist, granting the attackers initial network access. The group’s aggressive timeline – often demanding ransom within 30 minutes of gaining access – further increases the urgency for victims to respond.

Mandiant’s investigation revealed that the Silent Ransom Group employs tactics reminiscent of past campaigns, including the use of self-destructing messaging services like privnote.com to minimize forensic traces. They also leverage deceptive IT portal domains mimicking internal infrastructure. Once inside a network, the group focuses on acquiring legal and financial documents, including contracts, tax records, and merger files, often targeting document management platforms and cloud storage. The group’s actions are designed to cause reputational damage and trigger regulatory fines, as highlighted in their extortion letters.

The FBI has issued an advisory regarding this group’s tactics, confirming that they are conducting in-person data theft attacks, mirroring the methods used in previous BazarCall campaigns. This multi-faceted approach underscores the Silent Ransom Group’s adaptability and persistence, posing a significant risk to organizations, particularly those in the legal sector.

Read the full article at BleepingComputer