Silent Ransom Group’s Bold New Play: When Hackers Show Up at the Door

The FBI has warned that Silent Ransom Group now sends operatives to law firm offices to steal data via USB drives after social engineering calls fail. Active since 2022, the extortion gang skips encryption entirely and pressures victims through leaks and client calls. Organizations must verify every visitor and IT claim. The hybrid digital-physical tactic raises the stakes for all sectors holding sensitive information.
Silent Ransom Group’s Bold New Play: When Hackers Show Up at the Door
Written by Sara Donnelly

The call comes in. An employee picks up. The voice on the other end claims to work in the company’s own IT department. Something about a recent phishing attempt that needs urgent attention. Follow these steps. Download this tool. Grant remote access. Within minutes, sensitive files start moving.

But sometimes the remote route fails. That’s when the real surprise arrives. A stranger walks through the front door, badge in hand, story prepared. They need to image the machine or run a backup. They plug in a USB drive. Data walks out the building on physical media. No malware. No encryption. Just theft and threats.

This is the current playbook of the Silent Ransom Group. Also known as Luna Moth, Chatty Spider and UNC3753. The FBI laid it out in stark terms this week. The group has targeted U.S. law firms without pause since spring 2023. It operates across insurance, finance and healthcare too. Yet law practices remain the persistent focus. FBI Internet Crime Complaint Center alert.

SRG emerged in 2022. It formed after the Conti ransomware syndicate collapsed. Early operations relied on callback phishing. Emails mimicked subscription charges from familiar brands. Recipients were told to call a number to cancel. The voice on the line then guided them to remote access software. Simple. Effective. Low noise.

By spring 2026 the tactics sharpened. Actors now pose directly as the victim’s internal IT staff. They call or send emails urging contact. Once on the phone they direct the employee to a remote desktop session. Tools such as Zoho Assist, Quick Assist, AnyDesk, RustDesk, Syncro, Splashtop or Atera appear. These legitimate applications leave few traces. Antivirus rarely complains.

Failure triggers the physical option. A threat actor arrives at the office. The cover story usually involves imaging a device or creating a backup to mitigate the supposed phishing risk. The visitor inserts an external hard drive or USB. Data copies directly. Exfiltration happens offline. No network logs. No cloud upload alerts. Clean.

Once data sits in their hands the extortion begins. Ransom notes arrive by email. Demands range from one million to eight million dollars depending on the target. Actors threaten to sell the information or publish it on their leak site, business-data-leaks[.]com. They call the victim’s own employees or clients. Pressure builds from multiple directions. The goal stays consistent. Pay to prevent exposure. No files get locked. The damage comes from the data itself.

Law firms make attractive marks. Client records contain privileged information. Intellectual property. Settlement details. Regulatory filings. Exposure can destroy reputations and invite lawsuits. The group understands this. It tailors operations to the sector’s pain points.

“Silent was the first group to really just be targeting law firms, and they’ve targeted major law firms,” Cynthia Kaiser of Halcyon told CyberScoop. “The theft of data in and of itself is the biggest issue for the law firms, so they’re tailoring a lot of their operations around what they know about the sector.”

Allan Liska of Recorded Future noted the group’s willingness to invest effort. “There were probably a lot of times that this failed before it started succeeding because there’s a lot of trial-and-error involved,” he said in the same report. “Silent Ransom Group has seen the value especially in going after law firms, and so they’re willing to put the extra effort into it.”

The physical visits stand out. Ian Gray of Flashpoint observed that sending actual people carries real risk. Most actors avoid it. Technology usually suffices to hide identities. SRG accepts the danger for speed and stealth. Joe Slowik of Dataminr pointed to the human element. Workplace trust remains necessary. Constant suspicion slows everything down. Attackers exploit that tension.

Artifacts from these attacks prove sparse. SRG relies on living-off-the-land techniques. WinSCP or renamed versions of Rclone move data. Uploads head to Google Drive, Microsoft OneDrive or other cloud services. In-person jobs leave even less behind. The primary clues become unauthorized USB connections, unfamiliar visitors claiming IT affiliation, or sudden large data transfers.

The FBI compiled a clear list of warning signs. New unauthorized downloads of remote tools. External drive installations without approval. Connections from WinSCP or Rclone to unknown IPs. Emails or calls from unknown parties claiming data theft. Visits from individuals posing as support staff. Alerts that information left the environment. Phone calls to clients repeating the same claims.

Earlier warnings existed. A May 2025 FBI notification described the group’s callback campaigns. An EclecticIQ analysis that same period detailed domain registrations impersonating law firm IT portals. The latest alert builds on those. It confirms the evolution to physical access. It urges immediate attention from legal practices.

Recommendations follow standard lines yet gain fresh urgency. Verify every visitor’s credentials. Copy identification. Develop explicit policies on how IT support authenticates. Train staff to question unsolicited calls about system issues. Require phishing-resistant multifactor authentication wherever possible. Limit sensitive data access from remote or home networks. Consider blocking external drive use on critical machines. Maintain offline backups.

These steps sound familiar. Their application against a group that blends digital deception with physical presence demands tighter coordination. Cyber teams and physical security must speak the same language. Reception staff become the new front line. Executive assistants hold keys to the server room. Everyone requires awareness.

SRG claims more than 100 victims. Activity surged in recent months. It does not rank among the most prolific ransomware operators. Volume stays modest. Precision matters more. The group picks targets with care. It executes with speed. Data leaves before defenders notice. Extortion follows without the noise of encrypted files or public victim shaming in every case.

Yet the leak site exists. Some victims appear there. Jones Day, a prominent firm, saw its data posted in earlier incidents. The pressure works. Many organizations weigh the cost of silence against public embarrassment and legal exposure.

The shift to physical impersonation signals something larger. Cybercriminals adapt when digital defenses improve. Remote access tools face heavier scrutiny. Network monitoring catches unusual egress. But a polite visitor with a plausible story? That bypasses many controls. It turns the office itself into the vulnerability.

Organizations outside law firms should not feel safe. The FBI noted activity across multiple sectors. Any entity holding valuable or sensitive data qualifies. Healthcare records. Financial details. Insurance claims. All carry leverage.

Reporting remains critical. The FBI seeks ransom notes, phone numbers, email accounts, transcripts, original phishing messages, crypto wallet details and descriptions of the physical actors. Surveillance footage helps. Even partial information aids investigations.

The group operates from Russia, according to multiple analyses. Links to past BazarCall campaigns that fed Conti and Ryuk operations suggest experienced hands. Continuity exists even as names change.

Defenders face a hybrid threat. Digital indicators mix with physical ones. Logs show remote tool installs. Cameras capture unknown faces. Employees report strange calls and surprise visits. Connecting those dots quickly determines whether the incident stays small or escalates into eight-figure extortion.

SRG demonstrates patience. It refined callback phishing over years. It added vishing. Now it tests in-person operations. Each layer increases complexity and risk for the attackers. Each also raises the bar for victims. Simple awareness no longer suffices. Verification must become habit. Trust requires proof.

The FBI alert carries a clear message. This group persists. Its methods evolve. Law firms sit in the crosshairs today. Others could follow. Preparation beats reaction. Check visitor logs. Update access policies. Train relentlessly. And when that unexpected IT support call arrives, pause. Verify. Then verify again.

The door to the server room stays locked for a reason. Make sure only the right people hold the key.

Subscribe for Updates

CybersecurityUpdate Newsletter

The CybersecurityUpdate Email Newsletter is your essential source for the latest in cybersecurity news, threat intelligence, and risk management strategies. Perfect for IT security professionals and business leaders focused on protecting their organizations.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us