Cyber Gang Poses as Tech Support to Target Law Firms

by Sarah Steffens

A criminal group known as Silent Ransom Group has been tricking law firms into handing over sensitive data by impersonating information technology staff, the FBI has warned.

The group, also called Luna Moth, Chatty Spider, or UNC3753, focuses on stealing confidential files and threatening to release them unless a ransom is paid. Unlike many ransomware attackers who lock up computer systems, this group relies on the power of public exposure to pressure victims.

Law firms are a prime target because they store valuable client information, such as legal strategies, financial records, and intellectual property. A successful attack can harm both the firm and its clients.

Since spring 2023, the group has used phishing emails and phone calls to pose as IT support, convincing employees to grant remote access to their computers. In some cases, attackers have even sent people to law firm offices in person, pretending to be tech workers, to copy data onto external drives.

A report from Google Threat Intelligence and Mandiant noted similar tactics against U.S. legal and financial firms. While the FBI alert focused on the United States, European cybersecurity officials say the threat is not limited to one region. The European Union’s cybersecurity agency, ENISA, noted that cybercriminals increasingly steal data for extortion or follow-up attacks, and some ransomware operators now skip encryption entirely.

Stolen data can also be sold or used by other malicious actors, including state-linked groups or hacktivists, blurring the lines between cyber threats. ENISA highlighted that attackers are using indirect paths through service providers and supply chains.

Cybersecurity firm Resecurity reported in June that Silent Ransom Group operates public leak sites to pressure victims. The firm said it had downloaded over 1.6 million files from these sites, and some affected law firms may not know their data was exposed.

The FBI urges organizations to train staff to verify unexpected IT requests, limit remote access tools, watch for unusual logins, and report any incidents to authorities.