The Extortion Crew That Walks Through Your Front Door

Most cybercriminals try to break into your network remotely.

The Silent Ransom Group (SRG), also known as Luna Moth, Chatty Spider, and UNC3753, increasingly prefers a different approach: convincing your employees to let them in, or simply turning up at your office and plugging a device directly into a workstation.

The FBI’s latest FLASH alert highlights a threat actor that has evolved beyond traditional ransomware. Instead of encrypting systems, SRG focuses on rapid data theft and extortion, making many conventional security controls less effective. The lesson for organisations is clear: your biggest vulnerability may no longer be a firewall or endpoint, but a helpful employee trying to solve what appears to be an IT problem.

The Evolution of Extortion

For years, ransomware groups followed a familiar playbook.

Gain access. Move laterally. Encrypt systems. Demand payment.

The Silent Ransom Group has largely abandoned that model.

According to the FBI, the group’s objective is speed. Rather than spending days or weeks establishing persistence, escalating privileges, and deploying malware, SRG focuses on obtaining immediate access, stealing sensitive data, and using the threat of disclosure as leverage.

This reflects a broader trend across the cybercriminal ecosystem.

Encryption creates noise. Data theft creates leverage.

A victim may be able to restore systems from backup. Recovering leaked intellectual property, client records, legal documents, or executive communications is considerably harder.

The New Attack Chain

The group’s methodology is remarkably simple.

An employee receives a phishing email or phone call that appears to originate from internal IT support.

The employee is encouraged to contact a support number or engage with an individual claiming to be from the company’s technology team.

Once contact is established, the attacker persuades the employee to grant access through a legitimate remote administration tool. The FBI identifies common examples including AnyDesk, RustDesk, Splashtop, Zoho Assist, Quick Assist, Syncro, and Atera.

If that approach fails, the group has demonstrated a willingness to deploy an individual physically to the victim’s location.

The visitor claims to be from IT support and may explain that a backup, forensic image, or remediation action is required following a phishing incident. The objective is simple: gain access to a workstation and connect removable media for data collection.

From an intelligence perspective, this is notable because it combines cyber intrusion techniques with human intelligence tradecraft.

The attack succeeds not because the technology is sophisticated, but because the social engineering is believable.

Why Law Firms Are Being Targeted

The FBI notes that SRG has victimised organisations across multiple sectors including insurance, finance, and healthcare. However, US law firms have been a consistent focus since 2023.

The rationale is obvious.

Law firms possess:

  • Sensitive client communications.
  • Merger and acquisition information.
  • Litigation strategies.
  • Intellectual property.
  • Executive and political correspondence.

These organisations often maintain vast quantities of highly valuable information while operating under significant reputational constraints.

For many victims, public disclosure may be more damaging than operational disruption.

That makes extortion particularly effective.

The Security Control Nobody Likes Talking About

Most organisations have invested heavily in cyber security awareness.

Fewer have invested the same effort into physical verification procedures.

Consider the following scenario.

An individual arrives at reception wearing business attire and carrying a laptop bag. They claim to be from IT support. They reference a recent phishing incident that employees may already know about. They ask to access a workstation to complete remediation work.

Would your staff challenge them?

Would reception verify their identity?

Would they know who to call?

Many organisations spend millions on technology while assuming that nobody would simply walk through the front door.

The Silent Ransom Group is betting otherwise.

Indicators Intelligence Teams Should Monitor

The FBI identifies several behavioural indicators that may signal SRG activity:

  • Employees receiving unsolicited calls from individuals claiming to be internal IT support.
  • New installations of remote administration tools.
  • Unauthorised USB devices or external hard drives connected to company systems.
  • Unexpected transfers to cloud storage platforms such as OneDrive or Google Drive.
  • Use of WinSCP or Rclone to external destinations.
  • Unidentified visitors seeking access to corporate devices.

None of these indicators are particularly exotic.

That is precisely what makes the threat difficult to detect.

Most security tooling is optimised to identify malware. It is far less effective at identifying legitimate software being used by an authorised employee under false pretences.

Intelligence Lessons

There are three broader lessons here.

1. Human Access Is Often Easier Than Technical Access

Security teams frequently focus on perimeter controls, vulnerability management, and endpoint detection.

Attackers focus on people.

A convincing phone call remains one of the most effective intrusion techniques available.

2. Cyber and Physical Security Can No Longer Operate Separately

This campaign sits directly at the intersection of cyber security, protective security, and insider risk.

An organisation may have excellent cyber controls but still be vulnerable if reception staff, facilities teams, and end users are not integrated into the security process.

This is a classic converged security problem.

3. Data Theft Is Becoming More Important Than Encryption

Many organisations still structure ransomware preparedness around business continuity and disaster recovery.

That remains important.

However, the growing trend toward extortion-only operations means organisations should devote equal attention to identifying sensitive data holdings, reducing unnecessary retention, and understanding what information would cause the greatest harm if exposed.

What Organisations Should Do Next

The FBI recommends a series of straightforward defensive measures, including phishing-resistant MFA, visitor verification procedures, employee awareness training, and restricting the installation of external storage devices on systems handling sensitive information.

From a security intelligence perspective, I would add three questions:

  1. How would an employee verify a call from internal IT?
  2. How would reception verify an unexpected technology contractor?
  3. How quickly would security know if large volumes of sensitive data were copied to removable media?

If those questions cannot be answered confidently, the organisation may be more exposed than it realises.

The Silent Ransom Group demonstrates that modern extortion is no longer purely a cyber problem.

Sometimes the threat actor is not hiding behind a VPN.

Sometimes they’re standing in reception.