← BACK TO FEED
social engineeringvishinglaw firm securitydata extortionSilent Ransom Group

Fake IT Support Calls Are How This Gang Walks Into Law Firms and Walks Out With Everything

The Silent Ransom Group (also tracked as UNC3753/Luna Moth) is actively targeting U.S. law firms and professional services organisations using social engineering tactics, including fake IT support phone calls that trick employees into installing remote access tools, enabling data theft within hours. Once inside a network, attackers steal sensitive legal and financial documents before sending highly aggressive ransom demands — sometimes within 30 minutes of exiting the victim's environment — threatening to notify clients and regulators if payment is not made. Cybersecurity firm Mandiant and the FBI recommend organisations counter these attacks by enforcing strict IT verification procedures, limiting remote access tools, implementing multi-factor authentication, and training staff to recognise voice phishing attempts.

A cybercrime group called Silent Ransom Group is systematically hitting U.S. law firms and professional services companies with social engineering attacks that can go from first contact to data theft in a matter of hours. Mandiant published a detailed breakdown this week after the FBI put out a FLASH advisory warning about the same gang targeting the legal sector.

Mandiant tracks the group under the designation UNC3753, also known as Luna Moth or Chatty Spider. Between January and May 2026, the group went after dozens of organisations across legal, financial, and professional services. Law firms are the obvious sweet spot here: they hold enormous amounts of sensitive client data and face serious reputational and regulatory consequences if a breach goes public. The attackers know exactly how much pressure that creates.

The attack sequence is straightforward but effective. It starts with a phishing email, sent from a consumer account, that mimics an invoice or billing notice. No malicious links, no attachments. Just bait. The real move comes next: a follow-up phone call from someone pretending to be IT support, pushing the target to join a remote session via Teams, Zoom, Quick Assist, or Terminal Services. From there, the victim gets talked into installing a remote monitoring tool like AnyDesk, Zoho Assist, or Bomgar. At that point, the attackers are in.

This callback phishing approach is not new for these people. The same tactic was central to BazarCall campaigns that fed initial access into Ryuk and Conti ransomware operations years ago. After Conti collapsed in 2022, the group pivoted away from encryption-based ransomware entirely and rebuilt around pure data theft and extortion. Same operators, different model.

Mandiant also spotted phishing domains built to impersonate internal IT portals, following naming patterns like organisation-itdesk[.]com and organisation-helpdesk[.]com. The group uses Privnote, a self-destructing message service, to pass installation links and commands to targets during sessions, which cuts down on forensic traces left in browser histories or chat logs.

Once inside, they go straight for the good stuff: contracts, M&A documents, tax records, Social Security numbers, anything held in document management platforms or cloud storage. Exfiltration typically happens via WinSCP or Rclone. Then they leave, and within 30 minutes the victim gets an extortion letter.

The letters are deliberately brutal. Victims get three days to make contact and start negotiations. If they ignore it, the group threatens to call and email individual employees and clients directly to tell them about the breach. The letters are explicit about the consequences: destroyed client trust, regulatory fines, potential litigation. All of it designed to panic organisations into paying quietly.

The FBI advisory referenced in Mandiant's report flagged something even more brazen: in-person attacks. Attackers have been impersonating IT staff not just on phone calls but physically showing up at offices to image machines or make copies of files under the pretence of doing support work. Mandiant noted limited forensic evidence linking this directly to UNC3753 but assessed it as likely based on overlapping targets, timing, and operational patterns.

Separately, Resecurity published its own report this week finding that the group runs fast-flux DNS infrastructure to protect its data leak platforms. The technique rotates IP addresses rapidly across a pool of compromised devices, making takedowns considerably harder. The group's leak site relies on residential proxies spread across Latin America, Eastern Europe, Central Asia, the Middle East, and Asia.

Defence recommendations from both Mandiant and the FBI are practical rather than exotic: enforce strict verification procedures for any IT support interaction, restrict remote access tools and USB devices, apply MFA everywhere, and actually train staff to recognise voice phishing. The last one tends to get skipped. Given that the entire attack chain here depends on someone picking up a phone and following instructions from a stranger, it probably shouldn't be.

READ NEXT
AdaptHealth Blames Social Engineering After Patient Data Walks Out the DoorThis Cybersecurity Index Tracks Real Breaches and Refuses to Invent a Grand TotalCapital One Releases AI Vulnerability Hunter to the Public