Luna Moth
Actor Profile
Key Findings
- OriginEmerged March 2022 after the Conti syndicate's collapse, formed by former BazarCall operators; assessed Russia-based, tracked also as Silent Ransom Group and UNC3753.
- Primary TargetUS-based law firms since Spring 2023, with insurance and financial services as secondary targets; most tracked victims fall in the $10-50M revenue range.
- Initial AccessFake invoice callback phishing, direct vishing calls impersonating internal IT, and, since late 2025, in-person physical intrusion posing as IT support.
- Primary ObjectivePure data theft and single extortion client files, communications, and financial records exfiltrated, with no encryptor ever deployed.
- Operating MethodTalks victims into installing legitimate remote access software, or plants a USB device on-site, then exfiltrates sensitive files through that same session.
- Defense PrioritiesVerify unscheduled IT visitors in person, restrict which RMM tools can be installed, train staff on vishing scripts, and monitor for unusual outbound cloud transfers.
Kill Chain & MITRE ATT&CK Mapping
Luna Moth's tradecraft has gone through three deliberate phases since 2022, each adopted once defenders caught up with the last: fake invoice callback phishing, then direct vishing, then an operator walking through the front door.
Initial Access
An email claims the recipient was charged for a subscription service and provides a number to dispute it; calling connects to a live SRG operator posing as support staff.
Since March 2025 the group calls employees directly, identifying themselves as internal IT staff without an initiating email at all.
Since late 2025, an operator has in some cases traveled to the victim's physical office posing as IT support to gain hands-on access to a workstation, exploiting the gap between an organization's cyber and physical security programs.
They get in through fake invoice calls, direct IT-impersonation phone calls, or in some cases an operator showing up in person.
Execution & Persistence
The victim is talked through installing a legitimate remote monitoring and management tool under the pretense of processing a refund or resolving an IT issue, handing the operator full desktop control.
Where physical access is obtained, an operator manually plants a USB storage device on a target workstation to copy data directly, bypassing network based defenses entirely.
The victim is talked into installing legitimate remote-access software themselves, or an operator plugs in a USB drive if they're on-site.
Discovery
Once inside, operators focus on identifying and cataloguing the most sensitive available data, particularly client files and privileged legal documents, rather than broad network mapping.
Once inside, they go straight for the most sensitive client files rather than mapping the whole network.
Collection & Exfiltration
Identified data is exfiltrated in bulk to actor-controlled cloud storage using the same remote access session established at initial access, with no separate malware stage required.
Data is pulled out through the same remote session used to get in — no separate malware needed.
Impact
No encryption is deployed. The victim receives a high initial demand and a threat to publish the stolen data on the group's clearnet leak site, which lists company names, revenue, and sample records for non-paying victims.
No encryption is involved in this activity. The leverage comes from threatening to publish the stolen data unless the ransom is paid.
Indicators of Compromise
Because Luna Moth leans on legitimate tools and, increasingly, a live human at the front desk, the useful signal is procedural and behavioral rather than a malware hash.
Reported patterns & behavior
| Indicator / Behavior | Type | Notes |
|---|---|---|
| Fake subscription invoice email with a dispute phone number | Lure pattern | Original BazarCall-style entry point, still in limited use |
| Unsolicited call from "internal IT" requesting remote access | Behavior | Primary vector since March 2025 |
| Unrecognized visitor claiming to be IT support on-site | Physical security event | Confirmed tactic since late 2025; verify against a real work order |
| Legitimate RMM tool installed outside normal deployment process | Behavior | The group relies on trusted software rather than custom malware |
| Large outbound transfer to unfamiliar cloud storage endpoint | Network behavior | Consistent with the group's exfiltration-only playbook |
| Victim listed on a clearnet leak site with revenue and sample files | Post-incident indicator | Confirms extortion stage has begun |
None of these signals need a malware sample — an unscheduled "IT visitor" or an unexpected RMM install is often the clearest sign of this group.
Detection & Mitigation Priorities
Ordered by impact-to-effort ratio, with particular relevance to law firms and other professional services targets.
- P1Require verified, in-person identity checks for any unscheduled IT visitor, coordinated between physical security and IT rather than left to reception alone.
- P1Restrict which remote access / RMM tools can be installed and alert on installation of an approved tool from an unmanaged source or session.
- P1Train staff on both callback-invoice and direct-vishing scripts, since the group has used both and continues to adapt its opening pretext.
- P2Monitor for large or unusual outbound transfers to cloud storage, especially from endpoints tied to sensitive file shares.
- P2Lock down USB and removable storage device policy on workstations with access to sensitive client or case data.
- P3Monitor known leak sites for early mention of your organization ahead of a direct extortion contact.
Verifying IT visitors in person and locking down which remote-access tools can be installed closes off the group's two main entry points.
References
- 01Silent Ransom Group Targeting Law FirmsFederal Bureau of Investigation
- 02Silent Ransom Group Impersonating IT Personnel Through Vishing and Physical IntrusionFBI / IC3
- 03An Old Tactic Returns: SRG's Active Use of Physical Intrusion Against US Law FirmsHalcyon
- 04Ransomware in Focus: Luna MothS-RM
- 05Threat Actor Deep Dive: SilentSurefire Cyber
- 06Luna Moth Targets US Law Firms: $20M Ransom, 100+ AttacksShattered
- 07Luna Moth (Threat Actor)Malpedia