ctipilot.ch

Silent Ransom Group physical USB intrusions

campaign · campaign:fbi-flash-csa-260526-silent-ransom-group-physical-usb-attacks-us-law-firms single-source

FBI FLASH CSA 260526: Silent Ransom Group (Luna Moth / UNC3753) sends operatives physically into US law-firm offices to insert USB exfiltration devices when remote social engineering fails.

Aliases: Luna Moth, UNC3753

Coverage timeline
5
first 2026-05-28 → last 2026-06-06
Peak priority
high
1 high · 4 notable
Sources cited
17
10 hosts
Sections touched
5
active-threats, deep-dive, weekly-annual-reports
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
12
pinned v19.1 · see below
2026-05-285 appearances2026-06-06

ATT&CK techniques

12 techniques observed across 2 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1566Phishing×1

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.

Evidence: 2026-06-06/luna-moth-silent-ransom-group-unc3753-vishing-to-physical-ac · ATT&CK page ↗

T1566.004Phishing: Spearphishing Voice×1

Adversaries may use voice communications to ultimately gain access to victim systems. Spearphishing voice is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of manipulating a user into providing access to systems through a phone call or other forms of voice communications. Spearphishing frequently involves social engineering techniques, such as posing as a trusted source (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient.

Evidence: 2026-06-06/luna-moth-silent-ransom-group-unc3753-vishing-to-physical-ac · ATT&CK page ↗

Execution TA0002

T1204User Execution×1

An adversary may rely upon specific actions by a user in order to gain execution. Users may be subjected to social engineering to get them to execute malicious code by, for example, opening a malicious document file or link. These user actions will typically be observed as follow-on behavior from forms of Phishing.

Evidence: 2026-06-06/luna-moth-silent-ransom-group-unc3753-vishing-to-physical-ac · ATT&CK page ↗

T1204.002User Execution: Malicious File×1

An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.

Evidence: 2026-06-06/luna-moth-silent-ransom-group-unc3753-vishing-to-physical-ac · ATT&CK page ↗

Discovery TA0007

T1083File and Directory Discovery×1

Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Evidence: 2026-06-06/luna-moth-silent-ransom-group-unc3753-vishing-to-physical-ac · ATT&CK page ↗

T1135Network Share Discovery×1

Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement. Networks often contain shared network drives and folders that enable users to access file directories on various systems across a network.

Evidence: 2026-06-06/luna-moth-silent-ransom-group-unc3753-vishing-to-physical-ac · ATT&CK page ↗

Collection TA0009

T1074Data Staged×1

Adversaries may stage collected data in a central location or directory prior to Exfiltration. Data may be kept in separate files or combined into one file through techniques such as Archive Collected Data. Interactive command shells may be used, and common functionality within cmd and bash may be used to copy data into a staging location.

Evidence: 2026-06-06/luna-moth-silent-ransom-group-unc3753-vishing-to-physical-ac · ATT&CK page ↗

Command and Control TA0011

T1219Remote Access Tools×1

An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.

Evidence: 2026-06-06/luna-moth-silent-ransom-group-unc3753-vishing-to-physical-ac · ATT&CK page ↗

Exfiltration TA0010

T1052Exfiltration Over Physical Medium×1

Adversaries may attempt to exfiltrate data via a physical medium, such as a removable drive. In certain circumstances, such as an air-gapped network compromise, exfiltration could occur via a physical medium or device introduced by a user. Such media could be an external hard drive, USB drive, cellular phone, MP3 player, or other removable storage and processing device. The physical medium or device could be used as the final exfiltration point or to hop between otherwise disconnected systems.

Evidence: 2026-06-06/luna-moth-silent-ransom-group-unc3753-vishing-to-physical-ac · ATT&CK page ↗

T1052.001Exfiltration Over Physical Medium: Exfiltration over USB×2

Adversaries may attempt to exfiltrate data over a USB connected physical device. In certain circumstances, such as an air-gapped network compromise, exfiltration could occur via a USB device introduced by a user. The USB device could be used as the final exfiltration point or to hop between otherwise disconnected systems.

Evidence: 2026-06-06/luna-moth-silent-ransom-group-unc3753-vishing-to-physical-ac · 2026-06-01/luna-moth-unc3753-vishing-to-physical-usb-data-theft-extorti · ATT&CK page ↗

T1567Exfiltration Over Web Service×1

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.

Evidence: 2026-06-06/luna-moth-silent-ransom-group-unc3753-vishing-to-physical-ac · ATT&CK page ↗

T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage×1

Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.

Evidence: 2026-06-06/luna-moth-silent-ransom-group-unc3753-vishing-to-physical-ac · ATT&CK page ↗

Story timeline

  1. 2026-06-06Luna Moth / Silent Ransom Group (UNC3753): vishing-to-physical-access data-theft extortion against legal and professional services
    deep-dive
  2. 2026-06-01Sophos 2026 Active Adversary Report — identity the dominant intrusion root cause; Impacket and AnyDesk most-observed post-exploitation
    weekly-annual-reports
  3. 2026-06-01Luna Moth / UNC3753: vishing-to-physical-USB data-theft extortion reaches ~$20 M suppression payment and DNS fast-flux C2
    weekly-incidents-recap
  4. 2026-06-01Gamaredon — GammaPhish / GammaWorm / GammaSteel: Russian FSB campaign with USB worm and S3 exfiltration (Sekoia TDR part one)
    weekly-long-running
  5. 2026-05-28FBI FLASH CSA 260526 — Silent Ransom Group sends operatives physically into US law-firm offices to insert USB exfiltration devices when remote social engineering fails
    active-threatsFBI FLASH CSA 260526 — Silent Ransom Group sends operatives physically into US law-firm offices to insert USB exfiltration devices when remote social

Where this entity is cited

  • active-threats1
  • weekly-long-running1
  • weekly-incidents-recap1
  • weekly-annual-reports1
  • deep-dive1

Source distribution

  • attack.mitre.org8 (47%)
  • bleepingcomputer.com1 (6%)
  • blog.sekoia.io1 (6%)
  • cloud.google.com1 (6%)
  • cyberscoop.com1 (6%)
  • helpnetsecurity.com1 (6%)
  • legalcheek.com1 (6%)
  • securityaffairs.com1 (6%)
  • other2 (12%)

explore in graph

All cited sources (17)

Entries about Silent Ransom Group physical USB intrusions (5)

2026-06-06 · view entry permalink →

HIGH

Luna Moth / Silent Ransom Group (UNC3753): vishing-to-physical-access data-theft extortion against legal and professional services

Background and why this is a deep dive now. Luna Moth (also Silent Ransom Group / SRG, Chatty Spider, UNC3753) is a financially-motivated data-theft-and-extortion crew that has operated since 2022, originally tied to the BazarCall callback-phishing ecosystem. Its defining trait is the absence of ransomware: it does not encrypt, it steals and threatens publication. In May 2025 the FBI publicly warned that the group had spent roughly two years targeting US law firms via callback phishing (BleepingComputer, 2025-05-23). This brief covered the group's physical-intrusion escalation on 2026-05-28, when the FBI's 2026-05-26 Cyber FLASH (CSA 260526) reported operatives entering law-firm offices to insert USB exfiltration devices when remote social engineering failed. The reason for a fuller treatment now is three genuinely-new in-window developments: (1) Mandiant published a comprehensive primary forensic analysis on 2026-06-05 that supplies the kill-chain and ATT&CK detail the earlier news-only FBI-FLASH coverage lacked; (2) a major law firm reportedly paid ~$20 M in a suppression payment; and (3) the group moved its C2 onto DNS fast-flux infrastructure. The deep dive consolidates these into the actionable picture a defender needs — it does not re-report the physical-USB tactic as novel.

The 2026 campaign. Mandiant attributes a January-through-May 2026 data-theft extortion campaign against dozens of US professional-, legal- and financial-services organisations to UNC3753 (Mandiant, 2026-06-05). The intrusion is entirely social-engineered — there is no exploit in the chain. A benign invoice- or subscription-themed email establishes pretext; a follow-up vishing call impersonating internal IT support walks the target into hosting a screen-share session and installing a remote-access tool. Mandiant observed the actor convincing victims to install AnyDesk, Bomgar or Zoho Assist, and in one engagement to execute a "SuperOps RMM agent" via a cURL command. From there the actor pivots through BYOD or virtual desktops, enumerates file shares and document-management systems, then stages and exfiltrates using portable WinSCP or Rclone. The compression of the timeline is the operational headline: Mandiant notes that in many incidents the full sequence from first contact to data theft occurred within a single business day, and "Recently, Mandiant observed data searches, staging, and theft initiated in under an hour." Extortion follows by unbranded email, typically with a short deadline and a threat to publish on the actor's leak site.

The physical-access escalation (first flagged 2026-05-28, now forensically confirmed). The off-network tactic the FBI FLASH warned about is now corroborated in Mandiant's primary reporting: "individuals posing as IT technicians entered corporate offices to attempt direct exfiltration of data from an endpoint using USB storage media" (T1052.001 Exfiltration over Physical Medium). This bypasses every network-side control — egress filtering, RMM-installer detection, cloud-upload DLP — because the data never crosses the network perimeter. Visitor management and physical-security posture become a detection surface that EDR and log telemetry cannot cover.

Kill chain and ATT&CK mapping. Initial access via T1566.004 Spearphishing Voice and T1204.002 User Execution; remote access established through T1219 Remote Access Software; discovery via T1083 File and Directory Discovery and T1135 Network Share Discovery; collection and exfiltration via T1074 Data Staged, T1567.002 Exfiltration to Cloud Storage and, in the physical variant, T1052.001. The FBI's 2026-05-26 Cyber FLASH independently corroborates the campaign and underscores that, because no encryption is used and only legitimate remote-access and file-transfer tooling appears, conventional ransomware detections do not fire and few host artefacts remain (Help Net Security, 2026-05-27).

Why this run. Two in-window developments make this current rather than a recap of the 2025 FBI warning. First, a major US law firm, Weil, Gotshal & Manges, reportedly paid an estimated ~$20 M suppression payment after client data was stolen from an external cloud-storage site — an unusually large, fast (reportedly within days) payout that signals how high the leverage is when the stolen material is privileged legal data (Legal Cheek, 2026-06-03). Second, the group is hardening its operational infrastructure: a 2026-06-05 report documents SRG moving its command-and-control onto DNS fast-flux infrastructure, improving resilience against takedown and static-indicator blocking (Security Affairs, 2026-06-05).

Detection and hardening (no IOCs). Behavioural pivots: alert on RMM-agent installation (AnyDesk/Bomgar/Zoho/SuperOps) initiated from cmd.exe/powershell.exe or a cURL one-liner (Sysmon EID 1 with parent-process anomalies); flag portable WinSCP/Rclone execution from user-profile paths and high-volume outbound SSH/cloud-storage transfer sessions; watch document-management systems (e.g. iManage/SharePoint) for sudden keyword-search spikes and bulk downloads from VDI sessions. Hardening: block unauthorised RMM agents via WDAC/application control; restrict VDI/VPN authentication to corporate-managed devices with step-up MFA on BYOD; disable USB mass-storage write via GPO on sensitive endpoints; and — uniquely relevant given the in-person vector — enforce visitor credentialing and escort policies, and have help-desk staff verify any "IT support" callback against an out-of-band internal directory before granting remote or physical access. For Swiss and European legal and professional-services firms the campaign is directly transferable: the IT-helpdesk-impersonation vector is identical to the social-engineering pressure already seen across European corporate intrusions, and the physical-intrusion escalation raises a duty-of-care question that is squarely a physical-security, not just a SOC, problem.

threat06 Jun 05:00Zmulti-sourceOpen finding ↗

2026-06-01 · view entry permalink →

NOTABLE

Gamaredon — GammaPhish / GammaWorm / GammaSteel: Russian FSB campaign with USB worm and S3 exfiltration (Sekoia TDR part one)

Sekoia's first part of the Gamaredon series disclosed a January 2026 campaign arc (Sekoia TDR, 2026-06-01; daily 2026-06-02; update daily 2026-06-03). Initial access via CVE-2025-8088 (WinRAR path-traversal, widely unpatched) drops HTA payloads from xHTML attachments. GammaWorm's NTFS-ADS concealment and USB-propagation pattern is the signature detection challenge: filesystem timestamps are useless (ADS hides the worm content), and the worm spreads to any mounted drive and mapped share, meaning air-gap-adjacent workstations remain in scope. GammaSteel exfiltrates collected data directly to S3. Part two of the Sekoia series is outstanding and expected to detail further tooling. Open question: has the campaign reached any EU public-sector estate beyond its primary Ukrainian targets? The USB-propagation vector is exactly the mechanism Luna Moth used this week for physical office intrusion — conceptually distinct actors, coincidentally parallel technique.

synthesis01 Jun 05:00Zsingle-sourceOpen finding ↗
Sources: Sekoia TDR

2026-06-01 · view entry permalink →

NOTABLE

Sophos 2026 Active Adversary Report — identity the dominant intrusion root cause; Impacket and AnyDesk most-observed post-exploitation

Published 2 June (Sophos X-Ops; drawing on 661 IR/MDR cases; daily 2026-06-03). The findings that directly shift defender priorities: identity-based compromise — stolen/valid credentials, brute force, phishing — is the leading intrusion root cause, with missing or misconfigured MFA present in a majority of incidents. Time from initial access to Active Directory compromise has compressed materially. Impacket is among the most frequently observed post-exploitation toolkits; AnyDesk is the most-abused legitimate remote-access tool, consistent with this week's Luna Moth tradecraft. The recurring telemetry blind spots are the load-bearing findings: firewall logs were missing in roughly half of ransomware cases, and a meaningful share of compromised Windows Servers were running end-of-life builds. Practical hunt targets: alert on Impacket artefacts (impacket-named tool processes, secretsdump-style NTDS access, SMBExec/WMIExec parent processes); instrument the initial-access-to-DC-compromise window; inventory EOL Windows Servers; verify firewall log retention is complete before an incident, not during one. This is a single-vendor IR report; treat findings as directionally correct rather than statistically definitive without independent corroboration. [SINGLE-SOURCE]

annual-report01 Jun 05:00Zsingle-sourceOpen finding ↗

Earlier coverage (2)