FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data
The FBI has issued an alert regarding a new tactic employed by the Silent Ransom Group (SRG) involving physical intrusion to steal data from law firms and other organizations. SRG is impersonating IT support personnel, gaining access to systems through remote sessions and USB drive insertion, bypassing traditional security measures. This approach allows them to exfiltrate data without deploying ransomware, escalating the risk of data compromise.
The Silent Ransom Group (SRG) is utilizing a sophisticated and increasingly dangerous tactic: physically sending operatives to victim organizations to steal data. Initially relying on phishing emails and callback scams to gain initial access, SRG has now escalated its operations by posing as IT support staff and directly accessing systems via remote desktop sessions. Following unsuccessful remote access attempts, SRG personnel are dispatched to the victim's location to insert USB drives into computers, ostensibly for data imaging or backups, but in reality, to exfiltrate sensitive information. This method allows them to avoid detection by traditional security software and bypass MFA solutions.