FBI warns Silent Ransom Group targeting US law firms since 2023
Synopsis
Key Takeaways
The Federal Bureau of Investigation (FBI) has issued a formal warning that a sophisticated cybercrime collective is systematically targeting US-based law firms, impersonating internal IT personnel through phone calls, phishing emails, and even in-person office visits. The alert, published on 26 May, names the group as the Silent Ransom Group (SRG) — also tracked under aliases Luna Moth, Chatty Spider, and UNC3753 — which has been actively operating against American legal practices since Spring 2023.
How the Attack Unfolds
According to the FBI's FLASH alert, SRG operatives initiate contact either by calling employees directly or sending phishing emails that prompt staff to dial what appears to be an IT support line. Once a target is on the phone, the attacker instructs them to grant access to a remote desktop session — effectively handing over control of the machine.
'SRG actors either directly call or send phishing emails to urge employees to call the SRG actor posing as IT support,' the FBI stated. 'While on the phone, the SRG actor directs the employee to grant access to a remote desktop session.'
If remote access attempts are unsuccessful, the group escalates to physical intrusion. In this scenario, an operative visits the victim's office in person, telling staff they need to 'image the device or create a backup file to address potential impacts from the phishing email,' the FBI said.
Data Theft Over Encryption
What distinguishes SRG from conventional ransomware gangs is its deliberate avoidance of system encryption. Instead, the group prioritises 'rapid access to victim systems, immediate data exfiltration, and extortion through threats of public disclosure or sale of stolen data,' according to the FBI alert.
Once inside a network, attackers use tools such as WinSCP or concealed versions of Rclone to extract company data at speed. The stolen files are then transferred to cloud platforms including Google Drive and Microsoft OneDrive, making detection and recovery significantly harder.
Extortion Tactics and Victim Pressure
After exfiltrating data, SRG actors contact both company employees and clients directly, threatening to publish or sell the stolen information unless a ransom is paid. This dual-pressure approach — targeting the firm and its clients simultaneously — is designed to accelerate negotiations and maximise leverage, particularly in the legal sector where client confidentiality is paramount.
Warning Signs and FBI Recommendations
The FBI's alert identified several red flags organisations should monitor, including unauthorised downloads of remote access software such as Zoho Assist, AnyDesk, RustDesk, Splashtop, and Atera. Suspicious cloud data transfers, installation of external hard drives, and unsolicited calls from individuals claiming IT affiliation are also flagged as indicators of compromise.
The agency urged organisations to reinforce cyber hygiene through staff training, regular data backups, and phishing-resistant multi-factor authentication. It also recommended verifying the identity of all visitors accessing company premises and restricting remote access permissions on systems that handle sensitive data.
With law firms holding some of the most sensitive client data in any industry — from litigation strategy to financial disclosures — the FBI's warning signals an escalating threat to the legal sector that shows no signs of abating.