Silent Ransom Group Hits US Law Firms in Escalating Extortion Attacks
The Silent Ransom group is conducting a targeted extortion campaign against US law firms, utilizing a sophisticated multi-stage attack chain involving vishing, IT impersonation, and physical intrusions. Google’s Mandiant has linked the group’s activities to UNC3753, noting their rapid progression from initial access to data theft and ransom demands, often within an hour. This tactic leverages social engineering and remote access tools to steal sensitive data, posing a significant risk to legal and financial services firms.
The Silent Ransom group is currently targeting US legal, professional, and financial services firms with a data theft and extortion campaign. This operation employs a layered approach, combining phishing emails, voice impersonation (vishing), and physical office intrusions to gain access to victim environments. Initial contact typically involves a seemingly legitimate invoice-themed email, followed by a phone call from the attacker posing as IT support, leveraging social engineering to gain remote access. The group’s speed is notable, progressing from initial contact to data theft and extortion in under an hour in some cases, highlighting the urgency of the threat.
The attackers utilize various tools and techniques to maintain persistent access and exfiltrate data. This includes downloading RMM utilities like AnyDesk and Zoho Assist, exploiting Bring-Your-Own-Device (BYOD) remote work setups, and accessing Virtual Desktop Infrastructure (VDI) environments via Windows 365 and Citrix. They actively search for sensitive information within enterprise platforms like iManage, targeting tax records, client agreements, and personally identifiable information. Data is then transmitted using tools like WinSCP, Rclone, and direct cloud uploads.
Following data exfiltration, the group immediately issues an aggressive extortion demand, threatening public disclosure of the stolen data. This tactic aims to pressure victims into paying a ransom to prevent the release of sensitive information. The group is tracked as UNC3753, Luna Moth, and Chatty Spider, and is actively monitored by Mandiant.
