Silent Ransom Group: the new cyber blackmail that points to law with support calls and data theft

Author: Published 7 min de lectura 149 reading

The images in this article were generated with artificial intelligence. How we publish

The warning from Mandiant and the FBI about the group known as Silent Ransom Group (UNC3753, Luna Moth, Chatty Spider) should be read as a wake-up call: we are no longer just talking about emails with malicious links but a hybrid and fast extortion model that combines voice social engineering, legitimate remote access tools and a data escape infrastructure designed to evade blockades.

The method is simple and effective: an apparently harmless mail with an administrative claim - invoice, support request - induces the victim to return the call; the attacker, posing as a support, convinces the employee to start a remote session and install legitimate assistance software (AnyDesk, Zoho Assist, Bomgar, SuperOps). With this vector the actor gets direct access to document repositories, cloud management and storage platforms and can exfilter files within hours using tools such as Rclone or WinSCP.

Silent Ransom Group: the new cyber blackmail that points to law with support calls and data theft
Image generated with IA.

The risks to law and professional service firms are high because they handle concentrated and high value data: contracts in negotiation, tax returns, personal data and business secrets. The incentive to pay is cultural and economic The evolution of the actor is remarkable: from the Ryuk / Conti ecosystem and from BazarCall-type campaigns, the group no longer depends on encryption systems, but on the double lever of theft and immediate coercion. Resecurity, which analyzed the leak infrastructure, also documents the use of fast-flux techniques with residential addresses distributed globally to make it difficult to take-out and block the filtration sites, which complicates the traditional response based on block lists. The practical implications go beyond turning off a technical incident. There is legal and compliance exposure: obligations to notify customers and authorities, possible fines under data protection laws and risks of negligence claims. In addition, response teams must deal with minimum artifacts in the records if attackers use self-destruction links like Privnote to deliver instructions, which requires a different forensic strategy. In terms of defence, the recommendations of Mandiant and the FBI remain valid but must be implemented with operational rigour: to establish unwavering verification procedures for support requests, to require validated internal tickets before authorizing remote sessions and to prohibit the installation of remote control tools from personal accounts or links received by mail or telephone. The verification must be multi-channel and documented, it's not enough with a call that "sounds legitimate." At the technical level, it is appropriate to restrict and control the use of RMM: to maintain only corporate versions with centralized management, apply white lists of applications, limit administrator privileges, force second factor MFA into sensitive accesses and monitor EDR and SIEM telemetry to detect use of Rclone / WinSCP, side movements and mass exfiltration to PIs or unexpected domains. Block or at least monitor ephemeral messaging domains and educate about the use of self-destruction tools also helps to preserve evidence. Detection requires adjusting the usual recipe: alerts based on behavior patterns (sudden use of support tools, connections from unusual locations, sensitive keywords searches in documentary managers and traffic peaks to storage services) are more effective than purely static filters. In addition, DNS monitoring and fast-flux intelligence are essential to identify and mitigate flight portals before they win traction; technical research such as Resecurity explains how to identify this infrastructure: https: / / www.resecurity.com / blog / article / silent-ransom-group-srg-unCovering-dns-fast-flux-infrastructure. For legal and enforcement teams, it is essential to prepare response plans that include communication with clients, regulatory assessments and coordination with law enforcement. Consult and apply technical and public intelligence guides such as that published by Mandiant helps to understand tactics, techniques and procedures and to translate them into specific controls: https: / / cloud / google.com / blog / topics / amenat-intelligence / targeted-campaign-us-law-firms. If you suspect an intrusion, act quickly but with criteria: preserve evidence, isolate committed endpoints, change account credentials with privileges, invalidate tokens and persistent sessions, and activate your incident response plan with external forensic support if necessary. Do not trust the discretion promised by the extortor; the tactic of pressing for 72 hours and the threat of contacting external customers is part of the scheme to force immediate payments. Finally, the most resilient defense combines technology, processes and culture: practical training against vishing and callback phishing, table exercises and gap simulations to test marketing and verification protocols, and effective segregation of sensitive data to reduce impact if unauthorized access occurs. The signatures that integrate these elements will significantly reduce the advantage that groups like Silent Ransom have today.

The evolution of the actor is remarkable: from the Ryuk / Conti ecosystem and from BazarCall-type campaigns, the group no longer depends on encryption systems, but on the double lever of theft and immediate coercion. Resecurity, which analyzed the leak infrastructure, also documents the use of fast-flux techniques with residential addresses distributed globally to make it difficult to take-out and block the filtration sites, which complicates the traditional response based on block lists.

The practical implications go beyond turning off a technical incident. There is legal and compliance exposure: obligations to notify customers and authorities, possible fines under data protection laws and risks of negligence claims. In addition, response teams must deal with minimum artifacts in the records if attackers use self-destruction links like Privnote to deliver instructions, which requires a different forensic strategy.

In terms of defence, the recommendations of Mandiant and the FBI remain valid but must be implemented with operational rigour: to establish unwavering verification procedures for support requests, to require validated internal tickets before authorizing remote sessions and to prohibit the installation of remote control tools from personal accounts or links received by mail or telephone. The verification must be multi-channel and documented, it's not enough with a call that "sounds legitimate."

At the technical level, it is appropriate to restrict and control the use of RMM: to maintain only corporate versions with centralized management, apply white lists of applications, limit administrator privileges, force second factor MFA into sensitive accesses and monitor EDR and SIEM telemetry to detect use of Rclone / WinSCP, side movements and mass exfiltration to PIs or unexpected domains. Block or at least monitor ephemeral messaging domains and educate about the use of self-destruction tools also helps to preserve evidence.

Detection requires adjusting the usual recipe: alerts based on behavior patterns (sudden use of support tools, connections from unusual locations, sensitive keywords searches in documentary managers and traffic peaks to storage services) are more effective than purely static filters. In addition, DNS monitoring and fast-flux intelligence are essential to identify and mitigate flight portals before they win traction; technical research such as Resecurity explains how to identify this infrastructure: https: / / www.resecurity.com / blog / article / silent-ransom-group-srg-unCovering-dns-fast-flux-infrastructure.

Silent Ransom Group: the new cyber blackmail that points to law with support calls and data theft
Image generated with IA.

For legal and enforcement teams, it is essential to prepare response plans that include communication with clients, regulatory assessments and coordination with law enforcement. Consult and apply technical and public intelligence guides such as that published by Mandiant helps to understand tactics, techniques and procedures and to translate them into specific controls: https: / / cloud / google.com / blog / topics / amenat-intelligence / targeted-campaign-us-law-firms.

If you suspect an intrusion, act quickly but with criteria: preserve evidence, isolate committed endpoints, change account credentials with privileges, invalidate tokens and persistent sessions, and activate your incident response plan with external forensic support if necessary. Do not trust the discretion promised by the extortor; the tactic of pressing for 72 hours and the threat of contacting external customers is part of the scheme to force immediate payments.

Finally, the most resilient defense combines technology, processes and culture: practical training against vishing and callback phishing, table exercises and gap simulations to test marketing and verification protocols, and effective segregation of sensitive data to reduce impact if unauthorized access occurs. The signatures that integrate these elements will significantly reduce the advantage that groups like Silent Ransom have today.

Coverage

Related

More news on the same subject.