Ransomware Actors Show Up In Person to Steal Law Firm Data
The Silent Ransom Group (SRG), also known as Luna Moth and UNC3753, is targeting law firms through sophisticated social engineering tactics, including impersonating IT personnel and conducting in-person visits to gain access to systems and steal data. This group, active since 2022, focuses on data theft extortion, threatening to leak stolen information unless a ransom is paid. The FBI warns of this evolving tactic, highlighting the need for organizations to verify identities and monitor for suspicious activity.
The FBI has issued a warning regarding the Silent Ransom Group's (SRG) increasingly aggressive tactics, moving beyond traditional ransomware methods to directly target law firms. SRG is impersonating IT personnel via phone calls and phishing emails to gain access to victim computers, often utilizing legitimate remote access tools. A concerning development is the group's practice of sending individuals in person to law firm locations to physically access computers and exfiltrate data. This approach bypasses traditional encryption methods, focusing solely on data theft and subsequent extortion. Cynthia Kaiser of Halcyon’s Ransomware Research Center notes that the legal sector is a prime target due to sensitive client data and regulatory pressures.
SRG’s methods have evolved to include requesting access to remote desktop sessions and fabricating scenarios requiring data imaging or backups to gain access. They utilize tools like WinSCP and Rclone for data transfer, often leveraging cloud storage services or physical storage devices. The group’s shift to in-person visits is considered unusual, historically relying on English-speaking call center professionals. The FBI’s warning emphasizes the importance of vigilance, recommending organizations verify all individuals accessing company premises and monitor for suspicious downloads, unauthorized device installations, and connections to external IP addresses.
Recent data breach investigations, such as Verizon’s 2026 report, highlight the continued success of social engineering attacks, underscoring the need for organizations to proactively address these vulnerabilities. The group’s actions are particularly concerning given the lack of arrests or infrastructure disruptions to date, suggesting a potential base of operations in Russia.
