HomeSecurityFBI: Warns of phishing attacks by Silent Ransom Group

FBI: Warns of phishing attacks by Silent Ransom Group

The Federal Bureau of Investigation (FBI) has issued a new warning about the increasing activity of the Silent Ransom Group (SRG), also known by the aliases Luna Moth, Chatty Spider , and UNC3753. The group, which first emerged in 2022, has built its reputation through sophisticated callback phishingdisguised as seemingly legitimate subscription services.

Silent Ransom Group SRG phishing FBI

According to the latest information, since March 2025, SRG has changed its strategy, now opting for a direct approach via telephone. Its members impersonate IT department employees and approach unsuspecting users with the aim of gaining remote access to critical systems.

See also: Phishing emails distribute Horabot malware in Latin America

The new tactic is primarily targeting U.S.-based law firmsdue to the sensitivity of the data they handle. However, the risk extends to other vulnerable industries, such as healthcare and insurance companies, where client data is equally valuable.

Social Engineering & Remote Access Tools

The Silent Ransom Group uses social engineering to convince victims to install remote access software, such as Zoho Assist, Syncro, AnyDesk, Splashtop, and Atera. Typically, the attackers falsely pose as technical support attempting to fix a nonexistent problem or cancel a supposed subscription.

Once they gain access to a system, the group members act methodically, asking victims to leave their devices “on” and unattended—often overnight. They then use tools like WinSCP or modified versions of Rclone to extract files and sensitive data.

FBI: Warns of phishing attacks by Silent Ransom Group

Blackmail via email and phone

Once the data theft is complete, the Silent Ransom Group proceeds with extortionate ransom demands , either via email or phone calls to employees. Threats include publishing or selling the data, regardless of its content.

See also: New phishing attack abuses Blob URIs to bypass SEG

In fact, SRG does not follow a consistent pattern when it comes to posting stolen files. Sometimes it chooses to publish them on public websites, adding an element of unpredictability and increasing the psychological pressure on victims to give in to the demands.

Invisible attackers with legal tools

The FBI notes that the Silent Ransom Group takes great care to hide its tracks. Rather than using traditional malware, it leverages legitimate system tools, evading detection by most antiviruses and making it particularly difficult for cybersecurity teams to detect.

What the FBI recommends to organizations

In its latest report, the FBI urges organizations to adopt good cybersecurity practices to mitigate the SRG threat. Key recommendations include:

  • Staff training to recognize phishing attacks
  • Clear IT authentication protocols
  • Regular backups of critical data
  • Mandatory activation of 2FA (two-factor authentication) on all accounts

The Silent Ransom Group's rapid adaptation and inventive tactics make it clear that the attacks are not only based on code, but also on human gullibility.

See also: CoGUI: New phishing kit has targeted millions of users

FBI: Warning of suspicious activity linked to the group

The FBI is warning about specific signs of malicious activity that may indicate the presence of the Silent Ransom Group (SRG) on corporate systems. Key indicators include:

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

  • Unauthorized downloads of remote access tools like AnyDesk, Zoho Assist, or Atera
  • Suspicious connections via WinSCP or Rclone to external IP addresses
  • Unsolicited communications, usually by phone or email, impersonating IT personnel and claiming subscription problems or data breaches

The federal agency is urging potential victims to share any relevant information, such as ransom notes, phone numbers used in the threats, and phishing emails.

Source: gbhackers.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS