SendTech Times
Analysis
MARKET SIGNAL:

Silent Ransom Group Uses Fake IT Support Calls to Pressure Law Firms

Newsroom brief

Silent Ransom Group is targeting U.S. law firms and professional services organizations with fake IT support calls, remote access tools and rapid data-theft extortion. Mandiant links the activity to UNC3753, Luna Moth and Chatty Spider, while the FBI has warned of related social engineering and in-person theft attempts.

Verified against source materialEdited by SendTech Times Cybersecurity DeskSource: Bleepingcomputer
Silent Ransom Group Uses Fake IT Support Calls to Pressure Law Firms
Image source: BleepingComputer

Fake help desks put law-firm data at the center of the attack

Silent Ransom Group is using fake IT support calls to target U.S. law firms and professional services organizations, with Mandiant warning that data theft can follow within hours of the first contact.

The campaign is significant because the group is not relying on a conventional ransomware detonation.

Its pressure point is the legal sector’s concentration of sensitive client files and the reputational cost of a public data leak.

Mandiant tracks the actor as UNC3753 and also links it to the names Luna Moth and Chatty Spider.

The activity described in the report spans January to May 2026 and includes dozens of organizations across legal, financial and professional services.

The FBI also issued a FLASH advisory last week warning that U.S. law firms were being targeted through social engineering and in-person data theft attempts.

The intrusion starts with a benign-looking email and a voice call

The initial lure is deliberately low on malware indicators.

Attackers send invoice-themed phishing emails from consumer email accounts, but the messages do not carry malicious links or attachments.

Their role is to prepare the victim for a follow-up phone call in which the attacker impersonates corporate IT staff.

That callback model is familiar from BazarCall campaigns previously tied to Ryuk and Conti ransomware operations.

In this campaign, the attacker pushes the employee into a remote support session through Microsoft Teams, Zoom, Quick Assist or Microsoft Terminal Services.

During the session, the attacker steers the employee toward installing legitimate remote administration software.

The named tools include AnyDesk, Zoho Assist, Bomgar and SuperOps, and the installation gives the actor initial access without needing to defeat endpoint defenses through a malicious attachment.

Remote support tools become the path to legal files

Once inside, the group looks for sensitive legal and financial material.

The source lists contracts, tax records, Social Security numbers, merger and acquisition files, document management platforms and cloud storage repositories as targets.

Exfiltration is commonly performed with tools such as WinSCP or Rclone.

Mandiant also found phishing domains that imitate internal IT portals and use naming patterns designed to look like corporate help-desk infrastructure.

The group uses privnote[.]com to pass installation links and commands during support sessions.

Because the service destroys messages, the method can reduce evidence left in browser histories or corporate chat logs.

Extortion moves quickly after the theft

The operational tempo is one of the clearest warnings for law firms.

Mandiant says ransom demands often arrive within 30 minutes after the attackers leave a victim environment.

The letters give the organization a three-day deadline to respond and start negotiations.

If the victim does not engage, the actor threatens to contact employees and external clients directly.

The letters emphasize client trust, regulatory exposure and the possibility that clients could sue over data mishandling.

That pressure is tailored to legal services, where client confidentiality and deal files can be more damaging than downtime.

In-person theft remains an unresolved but connected risk

The FBI advisory adds another route: attackers impersonating IT staff by phone or email may try to visit offices physically to image computers or create backups while stealing files.

Mandiant said forensic evidence is limited, but it views the in-person activity as likely connected to UNC3753 because the targeting, timelines and behavior match.

Silent Ransom Group has been active since at least 2022, after earlier links to the Ryuk and Conti cybercrime ecosystem.

The group later shifted toward standalone data-theft extortion, where stolen information becomes the leverage instead of encrypted systems.

A separate Resecurity report says the gang is also using fast-flux infrastructure and residential IP addresses across multiple regions to protect data-leak platforms.

Defenses focus on verification and remote-access control

The practical response is not limited to email filtering.

Mandiant and the FBI recommend strict verification for IT support interactions, tighter control over remote access tools, MFA enforcement, USB storage restrictions and employee training against voice phishing.

For law firms and professional services organizations, the watchpoint is whether support workflows can prove the caller’s identity before a remote session begins.

The source does not confirm every in-person case as UNC3753, but it does show that the group’s current playbook combines voice-led social engineering, legitimate remote tools, rapid file theft and pressure tactics designed for high-value client data.

Share this article
inXf

Related articles

More
WindRelay And SpyNote Pair Drives Android Phone Fraud Workflow
Cybersecurity

WindRelay And SpyNote Pair Drives Android Phone Fraud Workflow

BleepingComputer reported that Group-IB investigated a WindRelay and SpyNote Android malware combination that used social engineering, remote device access and NFC relay fraud to move from a phone call to financial theft.

DeadLock Ransomware Uses Polygon To Keep Victim Chats Reachable
Cybersecurity

DeadLock Ransomware Uses Polygon To Keep Victim Chats Reachable

BleepingComputer reported that DeadLock ransomware now uses Polygon smart-contract lookups to refresh victim chat infrastructure while spreading extortion services across Session and Wasabi.

OpenAI Widens Cyber AI Access Through Vetted Security Partners
Cybersecurity

OpenAI Widens Cyber AI Access Through Vetted Security Partners

OpenAI is giving approved security vendors and services firms access to cyber AI models while keeping Astra under tighter review for potential misuse risk.

Cisco Unified CM Flaw Puts WebDialer Exposure Under Patch Pressure
Cybersecurity

Cisco Unified CM Flaw Puts WebDialer Exposure Under Patch Pressure

Cisco disclosed fixed-release guidance for a critical Unified Communications Manager flaw that can let attackers gain root privileges when WebDialer is enabled. Cisco PSIRT is aware of public proof-of-concept exploit code for CVE-2026-20230, though it has not found active exploitation or targeting. The immediate test is whether administrators patch Unified CM or disable WebDialer before proof-of-concept code turns into wider exposure.

Manchester Airports Group Breach Exposes Data On 8.7 Million Travellers
Cybersecurity

Manchester Airports Group Breach Exposes Data On 8.7 Million Travellers

Manchester Airports Group disclosed that personal data linked to about 8.7 million people was stolen from systems tied to airport parking, lounge, Fast Track and Wi-Fi services, while core airport operations continued.

276 Arrested in Dubai Following International Anti-Scam Operation
Cybersecurity

276 Arrested in Dubai Following International Anti-Scam Operation

In a groundbreaking operation, police from China, the U.S., and the UAE collaborated to dismantle a voice phishing organization in Dubai. A total of 276 suspects were apprehended, revealing a sophisticated scam targeting victims through social media. This effort highlights the growing international cooperation to combat cybercrime.

Azure Tenant Data Claims Put Fortune 500 Directories In Focus
Cybersecurity

Azure Tenant Data Claims Put Fortune 500 Directories In Focus

SecurityWeek reported that TheHatman is selling millions of records allegedly taken from Azure and Entra tenants, while Hudson Rock tied the likely access path to stolen credentials.

Iran-Linked Hackers Target Middle East Universities As Academic Attacks Rise
Cybersecurity

Iran-Linked Hackers Target Middle East Universities As Academic Attacks Rise

AGBI reported that Iran-linked groups have targeted academic, logistics and professional-services organisations in the Middle East as CrowdStrike recorded a 17 percent global rise in academic-sector cyber activity.

Keep Reading

More Stories

Latest
Buntar Aerospace Raises $16 Million To Expand Combat Drone AutonomyPoliticsOct 11, 2026Buntar Aerospace Raises $16 Million To Expand Combat Drone AutonomyUkrainian defense-tech company Buntar Aerospace raised $16 million to expand manufacturing, engineering hiring and autonomous drone systems beyond its reconnaissance hardware and combat software base.Vijil DART Tests Enterprise AI Agents With Adaptive Red TeamingCybersecurityOct 11, 2026Vijil DART Tests Enterprise AI Agents With Adaptive Red TeamingHelp Net Security reported that Vijil released DART, an adaptive red-teaming system that uses adversarial agents to test enterprise AI agents across tools, memory and multi-turn behavior.UK Fibre Deals Face Split Tests As Nexfibre And BT Reviews DivergePoliticsOct 11, 2026UK Fibre Deals Face Split Tests As Nexfibre And BT Reviews DivergeCapacity Media reported that UK regulators are applying competition and public-interest tests to separate broadband consolidation deals involving nexfibre, Netomnia, BT and TalkTalk.Enveda Raises $311M To Push AI-Discovered Medicines Deeper Into TrialsAIOct 11, 2026Enveda Raises $311M To Push AI-Discovered Medicines Deeper Into TrialsFrontier Enterprise reported that Enveda closed a $311 million round led by Catalio Capital Management after two early clinical readouts for PRISM-discovered medicines.Indian Startup Funding Falls To $122.9 Million Despite More DealsFintech & Digital PaymentsOct 11, 2026Indian Startup Funding Falls To $122.9 Million Despite More DealsIndian startups raised $122.9 million across 25 deals in the first week of October, led by DailyObjects, Lumio, Beyond Appliances and StockGro, while IPO and acquisition moves kept the pipeline active.Oxide Raises $445M to Scale Rack-Level Cloud HardwareChips & SemiconductorsOct 11, 2026Oxide Raises $445M to Scale Rack-Level Cloud HardwareOxide Computer raised $445 million in Series D funding led by Eclipse Capital as demand for its pre-integrated data centre racks exceeds supply and the company prepares GPU-capable hardware upgrades.IBM and Red Hat Backport Fixes for 400-Plus Open Source BugsCybersecurityOct 11, 2026IBM and Red Hat Backport Fixes for 400-Plus Open Source BugsIBM and Red Hat say Lightwell has remediated more than 400 previously unknown vulnerabilities in Java libraries, while the new Clearinghouse gives customers a way to submit dependencies for priority review and fixes.Upscale AI Pairs Nvidia Spectrum-X With Its Own SkyHammer FabricChips & SemiconductorsOct 11, 2026Upscale AI Pairs Nvidia Spectrum-X With Its Own SkyHammer FabricUpscale AI is building SkyHammer as a scale-up fabric for AI clusters while using Nvidia Spectrum-X for scale-out switches, a strategy that tests whether Ethernet-based designs can challenge proprietary accelerator domains.Anthropic Opens Free AI Vulnerability Scanner For Open SourceCybersecurityOct 11, 2026Anthropic Opens Free AI Vulnerability Scanner For Open SourceAnthropic is offering open-source projects free AI security scans, with model-generated reports that may speed vulnerability checks but arrive without human triage.Vatar Raises $500,000 After Lagos Life Browser Game Surges to 4.3 Million UsersAIOct 11, 2026Vatar Raises $500,000 After Lagos Life Browser Game Surges to 4.3 Million UsersVatar Inc. has raised a $500,000 angel round at a $10 million valuation after Lagos Life reached 4.3 million registered users, giving the young Nigerian browser-game company capital for product, marketing and hiring.Anthropic Program Pairs Claude With Infrastructure Security TeamsAIOct 10, 2026Anthropic Program Pairs Claude With Infrastructure Security TeamsAnthropic is pairing Claude models, its engineers and outside cybersecurity firms to scan critical infrastructure and open-source software for vulnerabilities, with an opt-in service for maintainers.ABC Shareholders Seek Board Seats After South Africa Market SanctionsPoliticsOct 10, 2026ABC Shareholders Seek Board Seats After South Africa Market SanctionsShareholders holding about 76% of Africa Bitcoin Corporation want a meeting to appoint two non-executive directors after South Africa's FSCA sanctioned three former Altvest executives.