Leaked chats attributed to Russia-based Silent Ransom Group, also known as Luna Moth and Chatty Spider, describe data-extortion operations targeting roughly 50 organizations, mostly U.S. law firms, and recruitment of U.S.-based operatives to physically steal information. The group steals data without encrypting victims’ files. Chainalysis linked cryptocurrency addresses in the archive to known group extortions, while an FBI alert independently documented impostors posing as IT personnel to access victims’ computers. The operators claimed that 27 firms paid approximately $207 million between April and September 2026, but that total has not been independently verified. Members also discussed kidnapping, sexual blackmail, intimidation, and recruiting U.S. sailors for information about submarine-based nuclear forces; the reporting provides no evidence these proposals were carried out.
Crystal Intelligence’s analysis found evidence of substantial payments and described laundering through single-use wallets, instant exchangers, a Moscow cash broker, Bitcoin-to-Zelle conversions, and property purchases supported by misleading source-of-funds explanations. Despite wallet-separation rules, one operator combined payouts, and smaller payments reached regulated exchanges, creating investigative leads. The chats also discussed weapons purchases, payments to defense-sector insiders, selling stolen defense information to Russia’s Ministry of Defense, and relaunching as Sleepless Threat; they do not establish Russian government sponsorship. Law firms should verify IT personnel before granting physical or computer access, while financial compliance teams can prioritize linked wallet transactions, exchange deposit accounts, suspicious crypto-to-fiat payments, and inconsistent explanations for high-value purchases.

TTPs, infrastructure, and targeting history in one profile.
25 events from the most recent confirmed update back to the earliest known activity.
DataBreaches published a follow-up presenting additional evidence challenging Silent Ransom Group's denial that its systems had been breached. The dispute over the purported leaked records remained unresolved.
An October 8 update reported that Silent Ransom Group had agreed to an interview while disputing the alleged leak's origin. The group denied that its systems had been breached or its chats leaked.
In September 2026, SRG members discussed relaunching under the name Sleepless Threat. The source describes a proposed rebranding, not a confirmed completed relaunch.
Blockchain records showed a recruiter receiving 4.727 BTC, approximately $300,000, from a 5.54 BTC source on a day when the chat claimed $17.5 million. Crystal could confirm the recipient payment but not the full claimed ransom amount.
Operators arranged to purchase weapons from a Ukraine-based dealer and posted a payment wallet on May 30. The source does not establish that the weapons were delivered or used.
Blank Rome confirmed a May 2026 breach in which an attorney was tricked into uploading files to Google Drive. Alleged SRG records list a $17.5 million payment from the firm, but the disclosure does not establish SRG attribution or confirm that payment.
The FBI warned that SRG had begun sending people with fake identification into victims' offices. Its alert described members posing as IT personnel to obtain physical access to victims' computers.
The recruiter spent two separate payouts in one transaction, creating an on-chain link between wallets that SRG's operational rules were intended to keep separate.
Crystal confirmed a 0.0448 BTC share payment associated with an April 3 claim of $275,000. The confirmed transfer supported the payout timing, not independent verification of the claimed ransom total.
SRG's operations lead instructed recipients to use fresh addresses, isolate each victim's funds, avoid consolidation and request unlinked cash-out deposit addresses. Recipients were also told to reject reused or 'unclean' wallets and delay cashing out.
The group began focusing on US law firms in 2023, exploiting the sensitivity of privileged client information and firms' reputational exposure to pressure victims into paying.
Silent Ransom Group emerged in 2022 as a Russia-based Conti successor. Its operators had previously run the BazarCall callback-phishing campaign that supplied access to Ryuk and Conti.
Truesec reported that purported leaked SRG chats included discussions of kidnapping business executives and using recruited agents to threaten victims’ leadership teams and families to compel extortion payments. The report did not establish whether these discussions reflected concrete operational planning or idle conversation.
Check Point analyzed purported SRG materials describing callers monitoring a separate chat during remote sessions, suggesting parallel endpoint activity by another operator, alongside preparations for 3CX telephony. It also identified a “Fake_Employee” project but found no corroboration of successful employee placement; the archive’s provenance and authenticity remain unverified.
Chainalysis linked cryptocurrency addresses in the archive to known Silent Ransom Group extortions. This corroborated a connection to the group but did not validate the archive's complete set of claims.
Crystal analyzed 5,692 exported messages and associated cryptocurrency flows, tracing approximately 37 BTC to wallets named in the chats and identifying wallet-linking mistakes and exchange deposits. It did not independently verify the deal board's claim that 27 firms paid approximately $207 million between April 3 and September 24, 2026.
An unidentified source posted thousands of purported SRG messages to a bespoke onion site in early October without stating a motive. The archive covered August 2025 through September 2026 and mixed apparent extortion records with proposals, abandoned plans and boasting.
The recruiter purchased property in Russia through a power of attorney and told the bank that the purchase funds came from savings. The chats also contained advice on using misleading inheritance, gift or private-loan explanations for proceeds.
One recorded negotiation progressed from a rejected $100,000 offer through increasingly larger amounts to a listed $6 million contract and 'gold' status. The designation represented the group's claim of payment rather than independent confirmation.
A chat channel created in May discussed recruiting US sailors through gay bars near naval bases to obtain secret information about submarine-based nuclear-force movements. Members collected information about bases and nearby establishments, but the messages did not show successful recruitment or acquisition of military information.
Crystal traced 4.75505224 BTC reaching a named wallet at 21:01 on May 4, when the chat claimed $19 million. The observed transfer did not verify the claimed total.
In April, the apparent leader proposed targeting a senior employee at a major contractor working with the US Army, suggesting a monetization approach different from ordinary ransom demands. Another member suggested payment from Russia's Ministry of Defense, but the archive established no ministry contact, commission or payment.
For February 20, Crystal traced a source wallet receiving 13.23 BTC, approximately $898,000, and paying 0.735 BTC to a recruiter following discussion of a $1 million settlement. The transfers did not independently establish the full settlement amount.
In an archived negotiation, a law firm's representative said an intruder entered its New York office and copied files onto a flash drive. Executives authorized a $1 million settlement but demanded proof that all physical and digital copies would be destroyed.
SRG posted Russian-language advertisements disguised as nightclub-promotion, courier and security jobs, then steered respondents toward physical infiltration roles. Advertisements for Miami, Orlando and New York offered nightclub promoters at least $300 per night.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
11 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcemalware.news
Open sourcetruesec.com
Open sourcemalware.news
Open sourcecybersecuritynews.com
Open sourcetherecord.media
Open sourcedatabreaches.net
Open sourcecrystalintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.