Silent Ransom Group (SRG), also known as Silent Ransom, Luna Moth, Chatty Spider, UNC3753, and Storm-0252, is a Russia-based, financially motivated cyberextortion group active since 2022. It emerged following the dissolution of Conti and primarily conducts data-theft extortion rather than encrypting victims’ systems. Its targets include professional services, financial services, and real estate organizations, with a pronounced focus on United States law firms. Confidential legal documents, privileged client information, and sensitive personal records provide leverage for demands backed by threats to publish or sell stolen data. The group maintains a leak site to disclose information from victims that do not pay. SRG uses callback phishing and telephone-based social engineering to obtain initial access. Early campaigns used fraudulent subscription invoices to induce recipients to call attacker-controlled telephone numbers. Operators also impersonate internal IT support personnel, using help desk, security-check, or data-migration pretexts to persuade employees to initiate remote support sessions or grant access through legitimate administration software. Legitimate remote management and file-transfer tools allow operators to collect and exfiltrate information while blending into routine business activity and reducing reliance on readily detectable malware. The group has also used people posing as IT personnel to seek physical access to victims’ offices and computers after unsuccessful remote access attempts. No confirmed Russian government sponsorship or direction has been established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
388 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Russian cyber-extortion group active since 2022 that reportedly does not deploy ransomware, instead using data-leak extortion against law firms and other organizations holding sensitive client information. It reportedly recruits agents to physically infiltrate victims and introduce malicious USB drives. Leaked chats also discuss physical coercion and recruiting agents to obtain intelligence from US military personnel for potential sale to the Russian government; the report cautions that these discussions may not represent concrete operational plans.
Russia-based cyberextortion group active since 2022 that uses data-leak extortion rather than ransomware encryption. It targets law firms and other organizations holding sensitive client information. Reporting describes recruitment of agents to infiltrate victim premises and insert malicious USB drives. Leaked chats also discuss kidnapping executives, threatening leadership teams and families, and obtaining intelligence from U.S. military personnel through sexual encounters for sale to the Russian government. The article cautions that these discussions may reflect idle conversation rather than concrete operational planning; state sponsorship is not established.
An onion site called “Luna Moth Files” allegedly published the group's internal chat files. Silent Ransom Group denied their authenticity. The excerpt does not establish whether the files are genuine or identify their publisher.
A financially motivated group conducting social engineering-led data theft and extortion, generally without encryption. Previously documented operations use callback phishing and IT staff impersonation to persuade victims to authorize remote access. An unverified archive published around October 5, 2026, purportedly shows coordinated researchers, callers, technical operators, negotiators, and payment handlers. Law firms are a prominent target: 42 of its 50 most recently observed victims were law firms. Claims concerning operator identities, confirmed payments, deepfakes, and successful fake-employee placements remain uncorroborated.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.