CyberzSOC

Publication detail
← Back to advisories & guidance

Silent Ransom Group Targeting Law Firms ↗ source

May 23, 2025 FBI Alert

Summary

23 May 2025 The following information is being provided by the FBI, with no guarantees or warranties, for potential use at the sole discretion of recipients to protect against cyber threats. This data is provided to help cyber security professionals and system administrators guard against the persistent malicious actions PIN Number of cyber actors. This PIN was coordinated with DHS/CISA. Please contact the FBI with any questions related to this Private Industry Notification via your local FBI Cyber Squad. The cyber threat actor Silent Ransom Group (SRG), also known as Luna Moth, Chatty Spider, and UNC3753, is targeting law firms using information technology (IT) themed social engineering calls, then sending an individual posing as an IT support employee to the firm inperson, after which they insert a storage device into a computer to steal sensitive data to extort the victims. While SRG has historically victimized companies in many sectors, starting Spring 2023, the group has consistently targeted US-based law firms, likely due to the highly sensitive nature of legal industry data. industry. However, most of SRG’s victims are law firms or companies with similar naming As of April 2025, SRG was observed changing their tactics to calling individuals and posing as an employee from the victim’s IT department.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.