The Federal Bureau of Investigation (FBI) has issued a new warning about the increasing activity of the Silent Ransom Group (SRG), also known by the aliases Luna Moth, Chatty Spider , and UNC3753. The group, which first emerged in 2022, has built its reputation through sophisticated callback phishingdisguised as seemingly legitimate subscription services.

According to the latest information, since March 2025, SRG has changed its strategy, now opting for a direct approach via telephone. Its members impersonate IT department employees and approach unsuspecting users with the aim of gaining remote access to critical systems.
See also: Phishing emails distribute Horabot malware in Latin America
The new tactic is primarily targeting U.S.-based law firmsdue to the sensitivity of the data they handle. However, the risk extends to other vulnerable industries, such as healthcare and insurance companies, where client data is equally valuable.
Social Engineering & Remote Access Tools
The Silent Ransom Group uses social engineering to convince victims to install remote access software, such as Zoho Assist, Syncro, AnyDesk, Splashtop, and Atera. Typically, the attackers falsely pose as technical support attempting to fix a nonexistent problem or cancel a supposed subscription.
Once they gain access to a system, the group members act methodically, asking victims to leave their devices “on” and unattended—often overnight. They then use tools like WinSCP or modified versions of Rclone to extract files and sensitive data.

Blackmail via email and phone
Once the data theft is complete, the Silent Ransom Group proceeds with extortionate ransom demands , either via email or phone calls to employees. Threats include publishing or selling the data, regardless of its content.
See also: New phishing attack abuses Blob URIs to bypass SEG
In fact, SRG does not follow a consistent pattern when it comes to posting stolen files. Sometimes it chooses to publish them on public websites, adding an element of unpredictability and increasing the psychological pressure on victims to give in to the demands.
Invisible attackers with legal tools
The FBI notes that the Silent Ransom Group takes great care to hide its tracks. Rather than using traditional malware, it leverages legitimate system tools, evading detection by most antiviruses and making it particularly difficult for cybersecurity teams to detect.
What the FBI recommends to organizations
In its latest report, the FBI urges organizations to adopt good cybersecurity practices to mitigate the SRG threat. Key recommendations include:
- Staff training to recognize phishing attacks
- Clear IT authentication protocols
- Regular backups of critical data
- Mandatory activation of 2FA (two-factor authentication) on all accounts
The Silent Ransom Group's rapid adaptation and inventive tactics make it clear that the attacks are not only based on code, but also on human gullibility.
See also: CoGUI: New phishing kit has targeted millions of users
FBI: Warning of suspicious activity linked to the group
The FBI is warning about specific signs of malicious activity that may indicate the presence of the Silent Ransom Group (SRG) on corporate systems. Key indicators include:
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
- Unauthorized downloads of remote access tools like AnyDesk, Zoho Assist, or Atera
- Suspicious connections via WinSCP or Rclone to external IP addresses
- Unsolicited communications, usually by phone or email, impersonating IT personnel and claiming subscription problems or data breaches
The federal agency is urging potential victims to share any relevant information, such as ransom notes, phone numbers used in the threats, and phishing emails.
Source: gbhackers.com
