Law Firms Hit by Silent Ransom Group In IT Support Impersonation Campaign

A brazen cyber extortion syndicate is escalating its attacks against U.S. law firms using a highly aggressive tactic: impersonating internal IT support both online and in person.

According to a recently declassified May 2026 FBI FLASH report, the Silent Ransom Group (SRG) is bypassing traditional cybersecurity defenses through sophisticated social engineering.

Instead of deploying complex malware to encrypt networks, these threat actors rely on deception, data theft, and ruthless extortion to force victims to comply.

The Silent Ransom Group, tracked by researchers as Luna Moth, Chatty Spider, and UNC3753, has consistently targeted law firms since early 2023.

Unlike conventional ransomware operators, SRG actors do not deploy file-locking payloads. Their primary objective is rapid initial access, immediate data exfiltration, and high-pressure extortion.

They weaponize stolen sensitive data by threatening to publish it on their dedicated leak site, business-data-leaks.com, while routinely calling a victimized firm’s clients to force ransom negotiations.

Silent Ransom Targets Firms

As of Spring 2026, SRG has pivoted to a highly localized IT support impersonation scheme. The threat actors initiate contact via phishing emails or direct phone calls, aggressively urging employees to connect with a fake IT helpdesk.

Once on the phone, the attacker manipulates the employee into installing legitimate remote administration tools, granting the syndicate an interactive remote desktop session.

If digital social engineering fails, SRG escalates to physical intrusion. The group physically dispatches an operative to the targeted company’s office.

Posing as IT personnel, the attacker claims they must urgently image a device to resolve a security alert. They then insert a USB or external hard drive directly into the victim’s computer to manually extract highly sensitive data.

Once access is secured, SRG minimally escalates privileges and immediately begins data exfiltration. The group typically funnels stolen files to internal cloud-sharing platforms such as Google Drive and Microsoft OneDrive.

They also utilize external servers using tools like WinSCP and disguised versions of Rclone.

According to ic3 research, because SRG relies heavily on legitimate system management software and valid cloud environments, traditional antivirus solutions often fail to detect their intrusions.

Security teams must rely on behavioral monitoring, strict access policies, and robust physical security to stop this threat.

Observed MITRE ATT&CK Techniques:

TacticTechniqueDescription
Initial AccessT1566Callback phishing emails using IT-themed lures
Social EngineeringT1598.004Voice phishing to impersonate internal IT support
ExecutionT1219Abuse of legitimate remote access software

Organizations that detect SRG activity or intercept ransom communications are heavily encouraged to report the incident to their local FBI field office.

It is critical to preserve any ransom notes, phishing emails, or physical surveillance footage of the fake IT personnel to assist in active investigations.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories