The images in this article were generated with artificial intelligence. How we publish
Security researchers have again documented a wave of directed extortion that combines voice-based social engineering (vishing) techniques with abuse of legitimate remote access tools. According to the firms that published the findings, the group identified as UNC3753 - also known in the press as Chatty Spider, Luna Moth or Silent Ransom Group - has exploited trust in corporate technical support to enter networks of legal offices, financial services and professional firms in the United States between January and May 2026.
The central tactic is simple and effective: create a plausible pretext via email and close the deal by phone. Correos without links or attachments, with issues of billing or data migration, serve only to justify a call. Since that conversation, victims are induced to start screen sharing sessions and install legitimate software such as AnyDesk, Zoho Assist or commercial RMM, which allows the attacker to move within the environment as if it were authorized personnel.

More worrying is the escalation described by the authorities: in addition to remote access, in several incidents the actors have physically sent staff to the offices posing as technicians to extract information via USB units or external disks. This double vector - social engineering remote and physical presence - significantly reduces the effectiveness of perimeter controls and authentication.
The consequences for legal offices and financial institutions are particularly serious. These objectives concentrate documents containing trade secrets, corporate agreements, tax declarations and sensitive personal data; the exposure of such material has regulatory, reputational and contractual impacts that go beyond the immediate cost of a negotiation with extortors.
From the technical point of view, the abuse of RMM and screen sharing tools is effective for three reasons: first, they are applications designed to give remote control and are usually allowed by IT policies; second, their installation through telephone-guided instructions overlooks many alerts; third, file transfers through legitimate utilities such as WinSCP or Rclone are mixed with legitimate traffic and complicate detection. In addition, the use of services that send notes that are self-destroyed to transmit instructions avoids permanent social engineering records.
What can an organization do today to reduce the risk? First, treat unsolicited technical support calls as potential incidents: implement a separate channel verification policy (call-back to a known corporate number, internal ticket check) and train all staff to never authorize facilities after a single call. Second, limit and control remote access tools: allow only organizational-managed solutions and apply white application lists (AppLocker, MDM policies), unapproved administrative account facility blocking and centralized monitoring of remote sessions.

In the physical field, strengthen the control of visitors and the management of external technicians: prior verification, verifiable credentials, physical accompaniment and prohibition of connecting USB devices to machines with sensitive information. At the infrastructure level, introduce restrictions for removable media through GPO or UEFI / firmware configurations, and consider solutions that give early detection capacity on new RDP / AnyDesk connections and on the execution of file transfer utilities.
Preparation and response are key: keep offline and immutable backups, register and freeze relevant logs (remote access log, mail records, MFA records, VPN / VDI log, video conference platform records), and have a response plan that includes legal advice and controlled communication with customers. After an intrusion, preserve evidence (forensic images) and contact the competent authorities; report and coordinate with entities such as the FBI or national cybersecurity agencies helps to map campaigns and mitigate regional risks. Information on mail fraud and general recommendations is available at the FBI: https: / / www.fbi.gov / scams-and-safety / common-scams-and-crimes / business-email-compromise, and practical guides for Ransomware and extortion resilience in the CISA: https: / / www.cisa.gov / ransomware.
Finally, organizations must assume that authentication alone is not enough against targeted attacks that exploit the human factor. Invest in realistic awareness programmes (including vishing exercises), simulate technical support incidents and review contracts with third parties that have remote access to sensitive systems. The combination of technical controls, verification procedures and physical surveillance reduces the opportunity window that actors like UNC3753 exploit to turn a credible call into a mass data leak.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...