Silent Ransom Group physical USB intrusions
campaign · campaign:fbi-flash-csa-260526-silent-ransom-group-physical-usb-attacks-us-law-firms
FBI FLASH CSA 260526: Silent Ransom Group (Luna Moth / UNC3753) sends operatives physically into US law-firm offices to insert USB exfiltration devices when remote social engineering fails.
Aliases: Luna Moth, UNC3753
Coverage
2
first 2026-05-28 → last 2026-06-06
Latest activity
2026-06-06
Luna Moth / Silent Ransom Group (UNC3753): vishing-to-physical-access data-theft extortion against legal and…
Peak priority
high
1 high · 1 notable
Targets
legal-services
sectors: legal-services, finance · regions: us, europe
Sources cited
15
8 hosts
2026-05-282 appearances2026-06-06
Action items (1)
Do-now tasks recorded on the entries about Silent Ransom Group physical USB intrusions, newest first. Check the date before acting on an older one.
- Harden against Luna Moth helpdesk-impersonation and physical intrusion (. Block unauthorised RMM agents via application control, require out-of-band verification of "IT support" callbacks, restrict VDI/VPN to managed devices, and (given the in-person USB vector) review visitor-credentialing/escort policy and USB-write GPO on sensitive endpoints. Brief cleared/research staff on the LinkedIn/job-platform recruitment tradecraft in § 1.2026-06-06Luna Moth / Silent Ransom Group (UNC3753)…
Defender insights
What each entry about Silent Ransom Group physical USB intrusions tells a defender to do, newest first.
Detection
Story timeline
- 2026-06-06Luna Moth / Silent Ransom Group (UNC3753): vishing-to-physical-access data-theft extortion against legal and professional services
- 2026-05-28FBI FLASH CSA 260526, Silent Ransom Group sends operatives physically into US law-firm offices to insert USB exfiltration devices when remote social engineering fails
ATT&CK techniques (12 across 6 tactics)
12 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessPhishing · Phishing: Spearphishing Voice
- ExecutionUser Execution · User Execution: Malicious File
- DiscoveryFile and Directory Discovery · Network Share Discovery
- CollectionData Staged
- Command and ControlRemote Access Tools
- ExfiltrationExfiltration Over Physical Medium · Exfiltration Over Physical Medium: Exfiltration over USB · Exfiltration Over Web Service · Exfiltration Over Web Service: Exfiltration to Cloud Storage
Initial Access TA0001
T1566Phishing×1
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.
Evidence: 2026-06-06/luna-moth-silent-ransom-group-unc3753-vishing-to-physical-ac · ATT&CK page ↗
T1566.004Phishing: Spearphishing Voice×1
Adversaries may use voice communications to ultimately gain access to victim systems. Spearphishing voice is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of manipulating a user into providing access to systems through a phone call or other forms of voice communications. Spearphishing frequently involves social engineering techniques, such as posing as a trusted source (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient.
Evidence: 2026-06-06/luna-moth-silent-ransom-group-unc3753-vishing-to-physical-ac · ATT&CK page ↗
Execution TA0002
T1204User Execution×1
An adversary may rely upon specific actions by a user in order to gain execution. Users may be subjected to social engineering to get them to execute malicious code by, for example, opening a malicious document file or link. These user actions will typically be observed as follow-on behavior from forms of Phishing.
Evidence: 2026-06-06/luna-moth-silent-ransom-group-unc3753-vishing-to-physical-ac · ATT&CK page ↗
T1204.002User Execution: Malicious File×1
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.
Evidence: 2026-06-06/luna-moth-silent-ransom-group-unc3753-vishing-to-physical-ac · ATT&CK page ↗
Discovery TA0007
T1083File and Directory Discovery×1
Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Evidence: 2026-06-06/luna-moth-silent-ransom-group-unc3753-vishing-to-physical-ac · ATT&CK page ↗
T1135Network Share Discovery×1
Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement. Networks often contain shared network drives and folders that enable users to access file directories on various systems across a network.
Evidence: 2026-06-06/luna-moth-silent-ransom-group-unc3753-vishing-to-physical-ac · ATT&CK page ↗
Collection TA0009
T1074Data Staged×1
Adversaries may stage collected data in a central location or directory prior to Exfiltration. Data may be kept in separate files or combined into one file through techniques such as Archive Collected Data. Interactive command shells may be used, and common functionality within cmd and bash may be used to copy data into a staging location.
Evidence: 2026-06-06/luna-moth-silent-ransom-group-unc3753-vishing-to-physical-ac · ATT&CK page ↗
Command and Control TA0011
T1219Remote Access Tools×1
An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.
Evidence: 2026-06-06/luna-moth-silent-ransom-group-unc3753-vishing-to-physical-ac · ATT&CK page ↗
Exfiltration TA0010
T1052Exfiltration Over Physical Medium×1
Adversaries may attempt to exfiltrate data via a physical medium, such as a removable drive. In certain circumstances, such as an air-gapped network compromise, exfiltration could occur via a physical medium or device introduced by a user. Such media could be an external hard drive, USB drive, cellular phone, MP3 player, or other removable storage and processing device. The physical medium or device could be used as the final exfiltration point or to hop between otherwise disconnected systems.
Evidence: 2026-06-06/luna-moth-silent-ransom-group-unc3753-vishing-to-physical-ac · ATT&CK page ↗
T1052.001Exfiltration Over Physical Medium: Exfiltration over USB×1
Adversaries may attempt to exfiltrate data over a USB connected physical device. In certain circumstances, such as an air-gapped network compromise, exfiltration could occur via a USB device introduced by a user. The USB device could be used as the final exfiltration point or to hop between otherwise disconnected systems.
Evidence: 2026-06-06/luna-moth-silent-ransom-group-unc3753-vishing-to-physical-ac · ATT&CK page ↗
T1567Exfiltration Over Web Service×1
Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.
Evidence: 2026-06-06/luna-moth-silent-ransom-group-unc3753-vishing-to-physical-ac · ATT&CK page ↗
T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage×1
Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.
Evidence: 2026-06-06/luna-moth-silent-ransom-group-unc3753-vishing-to-physical-ac · ATT&CK page ↗
Entries about Silent Ransom Group physical USB intrusions (2)
Where this entity is cited
Source distribution
- attack.mitre.org8 (53%)
- bleepingcomputer.com1 (7%)
- cloud.google.com1 (7%)
- cyberscoop.com1 (7%)
- helpnetsecurity.com1 (7%)
- legalcheek.com1 (7%)
- securityaffairs.com1 (7%)
- therecord.media1 (7%)
All cited sources (15)
- attack.mitre.org`T1052.001`https://attack.mitre.org/techniques/T1052/001/
- attack.mitre.org`T1074` Data Stagedhttps://attack.mitre.org/techniques/T1074/
- attack.mitre.org`T1083` File and Directory Discoveryhttps://attack.mitre.org/techniques/T1083/
- attack.mitre.org`T1135` Network Share Discoveryhttps://attack.mitre.org/techniques/T1135/
- attack.mitre.org`T1204.002` User Executionhttps://attack.mitre.org/techniques/T1204/002/
- attack.mitre.org`T1219` Remote Access Softwarehttps://attack.mitre.org/techniques/T1219/
- attack.mitre.org`T1566.004` Spearphishing Voicehttps://attack.mitre.org/techniques/T1566/004/
- attack.mitre.org`T1567.002` Exfiltration to Cloud Storagehttps://attack.mitre.org/techniques/T1567/002/
- bleepingcomputer.comBleepingComputer, 2025-05-23https://www.bleepingcomputer.com/news/security/fbi-warns-of-luna-moth-extortion-attacks-targeting-law-firms/
- cloud.google.comMandiant / Google Cloud GTIG, targeted campaign against US law firmshttps://cloud.google.com/blog/topics/threat-intelligence/targeted-campaign-us-law-firms/
- cyberscoop.comCyberScoophttps://cyberscoop.com/fbi-warning-silent-ransom-group-law-firms/
- helpnetsecurity.comHelp Net Securityhttps://www.helpnetsecurity.com/2026/05/27/fbi-silent-ransom-group-law-firms-social-engineering/
- legalcheek.comLegal Cheek, 2026-06-03https://www.legalcheek.com/2026/06/weil-reportedly-pays-up-to-20-million-after-hackers-steal-client-data/
- securityaffairs.comSecurity Affairs, 2026-06-05https://securityaffairs.com/193215/cyber-crime/silent-ransom-group-srg-switching-to-dns-fast-flux-infrastructure.html
- therecord.mediaThe Recordhttps://therecord.media/fbi-warns-hackers-visit-law-firms-to-steal-data