Group profile
Silent Ransom Group
Data-theft extortion group (no encryption) that spun out of the Conti collapse; active since at least 2022. Also tracked as Luna Moth, UNC3753, and Chatty Spider. Primarily targets U.S. law firms (since 2023), plus healthcare, insurance, and financial organizations. TTPs: callback/phishing emails, IT-helpdesk impersonation, tricking staff into granting remote-desktop access, and in-person visits claiming to need 'backups or imaging'; exfiltrates via external drives and cloud storage (Google Drive, OneDrive), then extorts. Subject of FBI IC3 public advisories (2025 and May 2026).
Sectors hit
Countries hit