Skip to content
The Nexus
Group profile0 claimed in last 30d0 total tracked

Silent Ransom Group

Forward this

Data-theft extortion group (no encryption) that spun out of the Conti collapse; active since at least 2022. Also tracked as Luna Moth, UNC3753, and Chatty Spider. Primarily targets U.S. law firms (since 2023), plus healthcare, insurance, and financial organizations. TTPs: callback/phishing emails, IT-helpdesk impersonation, tricking staff into granting remote-desktop access, and in-person visits claiming to need 'backups or imaging'; exfiltrates via external drives and cloud storage (Google Drive, OneDrive), then extorts. Subject of FBI IC3 public advisories (2025 and May 2026).

First seen: Jan 1 · 00:00 UTCTracked since: 2026-06-01 18:31:38
Sectors hit
  • No sector data yet.
Countries hit
  • No country data yet.
Recent claimed victims

No claimed victims tracked yet.