SendTech Times
Analysis
MARKET SIGNAL:

Silent Ransom Group Uses Fake IT Support Calls to Pressure Law Firms

Article summary

Silent Ransom Group is targeting U.S. law firms and professional services organizations with fake IT support calls, remote access tools and rapid data-theft extortion. Mandiant links the activity to UNC3753, Luna Moth and Chatty Spider, while the FBI has warned of related social engineering and in-person theft attempts.

Silent Ransom Group Uses Fake IT Support Calls to Pressure Law Firms
Image source: BleepingComputer

Fake help desks put law-firm data at the center of the attack

Silent Ransom Group is using fake IT support calls to target U.S. law firms and professional services organizations, with Mandiant warning that data theft can follow within hours of the first contact.

The campaign is significant because the group is not relying on a conventional ransomware detonation.

Its pressure point is the legal sector’s concentration of sensitive client files and the reputational cost of a public data leak.

Mandiant tracks the actor as UNC3753 and also links it to the names Luna Moth and Chatty Spider.

The activity described in the report spans January to May 2026 and includes dozens of organizations across legal, financial and professional services.

The FBI also issued a FLASH advisory last week warning that U.S. law firms were being targeted through social engineering and in-person data theft attempts.

The intrusion starts with a benign-looking email and a voice call

The initial lure is deliberately low on malware indicators.

Attackers send invoice-themed phishing emails from consumer email accounts, but the messages do not carry malicious links or attachments.

Their role is to prepare the victim for a follow-up phone call in which the attacker impersonates corporate IT staff.

That callback model is familiar from BazarCall campaigns previously tied to Ryuk and Conti ransomware operations.

In this campaign, the attacker pushes the employee into a remote support session through Microsoft Teams, Zoom, Quick Assist or Microsoft Terminal Services.

During the session, the attacker steers the employee toward installing legitimate remote administration software.

The named tools include AnyDesk, Zoho Assist, Bomgar and SuperOps, and the installation gives the actor initial access without needing to defeat endpoint defenses through a malicious attachment.

Remote support tools become the path to legal files

Once inside, the group looks for sensitive legal and financial material.

The source lists contracts, tax records, Social Security numbers, merger and acquisition files, document management platforms and cloud storage repositories as targets.

Exfiltration is commonly performed with tools such as WinSCP or Rclone.

Mandiant also found phishing domains that imitate internal IT portals and use naming patterns designed to look like corporate help-desk infrastructure.

The group uses privnote[.]com to pass installation links and commands during support sessions.

Because the service destroys messages, the method can reduce evidence left in browser histories or corporate chat logs.

Extortion moves quickly after the theft

The operational tempo is one of the clearest warnings for law firms.

Mandiant says ransom demands often arrive within 30 minutes after the attackers leave a victim environment.

The letters give the organization a three-day deadline to respond and start negotiations.

If the victim does not engage, the actor threatens to contact employees and external clients directly.

The letters emphasize client trust, regulatory exposure and the possibility that clients could sue over data mishandling.

That pressure is tailored to legal services, where client confidentiality and deal files can be more damaging than downtime.

In-person theft remains an unresolved but connected risk

The FBI advisory adds another route: attackers impersonating IT staff by phone or email may try to visit offices physically to image computers or create backups while stealing files.

Mandiant said forensic evidence is limited, but it views the in-person activity as likely connected to UNC3753 because the targeting, timelines and behavior match.

Silent Ransom Group has been active since at least 2022, after earlier links to the Ryuk and Conti cybercrime ecosystem.

The group later shifted toward standalone data-theft extortion, where stolen information becomes the leverage instead of encrypted systems.

A separate Resecurity report says the gang is also using fast-flux infrastructure and residential IP addresses across multiple regions to protect data-leak platforms.

Defenses focus on verification and remote-access control

The practical response is not limited to email filtering.

Mandiant and the FBI recommend strict verification for IT support interactions, tighter control over remote access tools, MFA enforcement, USB storage restrictions and employee training against voice phishing.

For law firms and professional services organizations, the watchpoint is whether support workflows can prove the caller’s identity before a remote session begins.

The source does not confirm every in-person case as UNC3753, but it does show that the group’s current playbook combines voice-led social engineering, legitimate remote tools, rapid file theft and pressure tactics designed for high-value client data.

Share this article
inXf

Related articles

More
Check Point VPN Exploitation Puts Legacy IKEv1 Access In The Ransomware Spotlight
Cybersecurity

Check Point VPN Exploitation Puts Legacy IKEv1 Access In The Ransomware Spotlight

A critical Check Point VPN flaw, CVE-2026-50751, is being exploited against legacy IKEv1 remote-access configurations, with activity tied in one case to a Qilin ransomware affiliate and a second related VPN issue also disclosed.

Smart TV Proxy SDKs Turn Free Apps Into a Hidden AI Scraping Supply Chain
Cybersecurity

Smart TV Proxy SDKs Turn Free Apps Into a Hidden AI Scraping Supply Chain

Bright Data's SDK has been reverse-engineered in research showing how free apps can turn consumer devices, including smart TVs, into residential proxy nodes for web-scraping traffic. The issue matters because AI data harvesting is increasing demand for residential IPs, while consent screens and background network behavior may not be clear to users or IT teams.

NFSP Ransomware Attack Turns Supplier Email Pause Into a Security-Control Test
Cybersecurity

NFSP Ransomware Attack Turns Supplier Email Pause Into a Security-Control Test

The National Federation of Subpostmasters was hit by ransomware after a cPanel-related hosting software bug was exploited. The NFSP was targeted on 30 April, and the Post Office paused some email interactions with the federation while saying branch operations were not affected. The immediate test is whether trusted communications can resume without pushing subpostmasters toward insecure workaround channels.

Cisco Unified CM Flaw Puts WebDialer Exposure Under Patch Pressure
Cybersecurity

Cisco Unified CM Flaw Puts WebDialer Exposure Under Patch Pressure

Cisco disclosed fixed-release guidance for a critical Unified Communications Manager flaw that can let attackers gain root privileges when WebDialer is enabled. Cisco PSIRT is aware of public proof-of-concept exploit code for CVE-2026-20230, though it has not found active exploitation or targeting. The immediate test is whether administrators patch Unified CM or disable WebDialer before proof-of-concept code turns into wider exposure.

Keep Reading

More Stories

Latest
Sandstone Raises $30M For AI Workflow Tools In Company Legal TeamsScience & TechJun 10, 2026Sandstone Raises $30M For AI Workflow Tools In Company Legal TeamsSandstone raised $30 million in Series A funding led by Lightspeed Venture Partners to build AI workflow tools for in-house legal teams at small and mid-sized businesses.SpaceX Fixed-Price IPO Turns Retail Allocation Into The Main Market TestScience & TechJun 10, 2026SpaceX Fixed-Price IPO Turns Retail Allocation Into The Main Market TestSpaceX is offering IPO shares at a fixed $135 price, leaving allocation of roughly $75 billion in shares, especially retail access, as the main test before Thursday offering and Friday trading.UAE Salary Deadline Turns WPS Payroll Into A First-Of-Month Payments TestFintech & Digital PaymentsJun 10, 2026UAE Salary Deadline Turns WPS Payroll Into A First-Of-Month Payments TestUAE private-sector salary rules triggered a sharp WPS payroll surge on June 1, with Al Ansari Exchange up more than 151 per cent and Al Fardan Exchange up 136 per cent, turning wage compliance into a first-of-month payments and cash-flow test.Sabertooth's $500 Million SPV Push Turns AI Startup Access Into A ProductAIJun 10, 2026Sabertooth's $500 Million SPV Push Turns AI Startup Access Into A ProductSabertooth Capital has invested nearly $500 million into 10 late-stage AI and deep-tech companies through single-deal SPVs, showing how access to scarce private technology rounds is becoming a product of its own.Google's $4.99 AI Plus Cut Turns Consumer AI Into A Bundle FightAIJun 10, 2026Google's $4.99 AI Plus Cut Turns Consumer AI Into A Bundle FightGoogle cut AI Plus from $7.99 to $4.99 per month and doubled included storage to 400 gigabytes, pushing U.S. consumer AI subscriptions toward lower-priced platform bundles.GM Sodium-Ion Storage Push Turns AI Data Center Power Into A Battery Market TestCloud & Data CentersJun 10, 2026GM Sodium-Ion Storage Push Turns AI Data Center Power Into A Battery Market TestGeneral Motors is expanding into grid-scale energy storage through Peak Energy, LG Energy Solution and Redwood Materials, making AI data center demand a battery commercialization test.NAVER’s 55-Megawatt NVIDIA Buildout Tests Sovereign AI Cloud DemandCloud & Data CentersJun 9, 2026NAVER’s 55-Megawatt NVIDIA Buildout Tests Sovereign AI Cloud DemandNAVER and NVIDIA are expanding sovereign AI infrastructure from a 55-megawatt starting point toward gigawatt scale, tying Korea’s AI factory ambitions to DSX software, GAK Sejong capacity and localized model services.UAE Retail Forecast Turns AI And Luxury Spending Into A $227 Billion Market TestEconomyJun 9, 2026UAE Retail Forecast Turns AI And Luxury Spending Into A $227 Billion Market TestThe UAE retail sector is forecast to reach $227.1 billion by 2033, while smart retail is projected to grow more than twelvefold as luxury demand, tourism, grocery growth and AI-enabled retail systems reshape the market.Perplexity’s 2028 IPO Plan Puts AI Search On The Mega-Listing WatchlistAIJun 9, 2026Perplexity’s 2028 IPO Plan Puts AI Search On The Mega-Listing WatchlistPerplexity CEO Aravind Srinivas said the AI search company is still planning a 2028 IPO as Anthropic, OpenAI and SpaceX prepare large listings that could reset AI valuation expectations.Samsung 5G Uplink Test Puts Fixed Wireless On A Late-2027 Upgrade ClockScience & TechJun 9, 2026Samsung 5G Uplink Test Puts Fixed Wireless On A Late-2027 Upgrade ClockSamsung expects advanced 5G uplink technology similar to its MediaTek test to commercialize around late 2027, with 670 Mbps trial throughput pointing to fixed-wireless and AI workload gains that still need live-network proof.UAE-US $1.4tn Investment Pipeline Puts Abu Dhabi AI Campus On The Delivery ClockEconomyJun 9, 2026UAE-US $1.4tn Investment Pipeline Puts Abu Dhabi AI Campus On The Delivery ClockThe UAE and US reviewed a $1.4tn ten-year investment pipeline spanning AI, energy and manufacturing, with Abu Dhabi’s planned 5 gigawatt AI campus emerging as the clearest infrastructure benchmark.Zepto IPO Filing Tests Quick-Commerce Growth Against Losses And Valuation GapScience & TechJun 9, 2026Zepto IPO Filing Tests Quick-Commerce Growth Against Losses And Valuation GapZepto IPO filing shows rapid fiscal 2026 revenue, order and advertising growth, but widening losses, valuation pressure and a disclosed Enforcement Directorate inquiry create the main tests for its India listing.