05/28/2026
Yesterday the FBI released an advisory on the Silent Ransom Group (SRG), aka Luna Moth, Chatty Spider, and UNC3753, who use social engineering techniques like phone calls and phishing emails to access victim computers. SRG actors have been steadily targeting law firms since 2023, and they focus on accessing victim systems, exfiltrating data, and extorting their victims by threatening to release or sell the stolen data.
Since SRG actors use legitimate remote access tools, there are few artifacts of their attacks. Review the advisory to learn how SRG actors operate to exfiltrate data and potential signs of SRG activity: https://www.ic3.gov/CSA/2026/260526.pdf.