Threat Actor Profile
Dalton Hunter
August 2026
Threat Actor Profile: Data Extortion Without Encryption, Legal Sector Focus

Luna Moth

aka Silent Ransom Group (SRG) · Chatty Spider · UNC3753 · LeakedData
Threat Level: High
Section 01

Actor Profile

Key Findings

  • OriginEmerged March 2022 after the Conti syndicate's collapse, formed by former BazarCall operators; assessed Russia-based, tracked also as Silent Ransom Group and UNC3753.
  • Primary TargetUS-based law firms since Spring 2023, with insurance and financial services as secondary targets; most tracked victims fall in the $10-50M revenue range.
  • Initial AccessFake invoice callback phishing, direct vishing calls impersonating internal IT, and, since late 2025, in-person physical intrusion posing as IT support.
  • Primary ObjectivePure data theft and single extortion client files, communications, and financial records exfiltrated, with no encryptor ever deployed.
  • Operating MethodTalks victims into installing legitimate remote access software, or plants a USB device on-site, then exfiltrates sensitive files through that same session.
  • Defense PrioritiesVerify unscheduled IT visitors in person, restrict which RMM tools can be installed, train staff on vishing scripts, and monitor for unusual outbound cloud transfers.
Section 02

Kill Chain & MITRE ATT&CK Mapping

Luna Moth's tradecraft has gone through three deliberate phases since 2022, each adopted once defenders caught up with the last: fake invoice callback phishing, then direct vishing, then an operator walking through the front door.

01

Initial Access

An email claims the recipient was charged for a subscription service and provides a number to dispute it; calling connects to a live SRG operator posing as support staff.

Since March 2025 the group calls employees directly, identifying themselves as internal IT staff without an initiating email at all.

Physical Impersonation / On-Site Intrusion

Since late 2025, an operator has in some cases traveled to the victim's physical office posing as IT support to gain hands-on access to a workstation, exploiting the gap between an organization's cyber and physical security programs.

Analyst Note

They get in through fake invoice calls, direct IT-impersonation phone calls, or in some cases an operator showing up in person.

02

Execution & Persistence

The victim is talked through installing a legitimate remote monitoring and management tool under the pretense of processing a refund or resolving an IT issue, handing the operator full desktop control.

Physical Storage Device Insertion

Where physical access is obtained, an operator manually plants a USB storage device on a target workstation to copy data directly, bypassing network based defenses entirely.

Analyst Note

The victim is talked into installing legitimate remote-access software themselves, or an operator plugs in a USB drive if they're on-site.

03

Discovery

Sensitive File & Share Discovery

Once inside, operators focus on identifying and cataloguing the most sensitive available data, particularly client files and privileged legal documents, rather than broad network mapping.

Analyst Note

Once inside, they go straight for the most sensitive client files rather than mapping the whole network.

04

Collection & Exfiltration

Identified data is exfiltrated in bulk to actor-controlled cloud storage using the same remote access session established at initial access, with no separate malware stage required.

Analyst Note

Data is pulled out through the same remote session used to get in — no separate malware needed.

05

Impact

Single Extortion via Leak Site

No encryption is deployed. The victim receives a high initial demand and a threat to publish the stolen data on the group's clearnet leak site, which lists company names, revenue, and sample records for non-paying victims.

Analyst Note

No encryption is involved in this activity. The leverage comes from threatening to publish the stolen data unless the ransom is paid.

Section 03

Indicators of Compromise

Because Luna Moth leans on legitimate tools and, increasingly, a live human at the front desk, the useful signal is procedural and behavioral rather than a malware hash.

Reported patterns & behavior

Indicator / BehaviorTypeNotes
Fake subscription invoice email with a dispute phone numberLure patternOriginal BazarCall-style entry point, still in limited use
Unsolicited call from "internal IT" requesting remote accessBehaviorPrimary vector since March 2025
Unrecognized visitor claiming to be IT support on-sitePhysical security eventConfirmed tactic since late 2025; verify against a real work order
Legitimate RMM tool installed outside normal deployment processBehaviorThe group relies on trusted software rather than custom malware
Large outbound transfer to unfamiliar cloud storage endpointNetwork behaviorConsistent with the group's exfiltration-only playbook
Victim listed on a clearnet leak site with revenue and sample filesPost-incident indicatorConfirms extortion stage has begun
Analyst Note

None of these signals need a malware sample — an unscheduled "IT visitor" or an unexpected RMM install is often the clearest sign of this group.

Section 04

Detection & Mitigation Priorities

Ordered by impact-to-effort ratio, with particular relevance to law firms and other professional services targets.

  • P1Require verified, in-person identity checks for any unscheduled IT visitor, coordinated between physical security and IT rather than left to reception alone.
  • P1Restrict which remote access / RMM tools can be installed and alert on installation of an approved tool from an unmanaged source or session.
  • P1Train staff on both callback-invoice and direct-vishing scripts, since the group has used both and continues to adapt its opening pretext.
  • P2Monitor for large or unusual outbound transfers to cloud storage, especially from endpoints tied to sensitive file shares.
  • P2Lock down USB and removable storage device policy on workstations with access to sensitive client or case data.
  • P3Monitor known leak sites for early mention of your organization ahead of a direct extortion contact.
Analyst Note

Verifying IT visitors in person and locking down which remote-access tools can be installed closes off the group's two main entry points.

Section 05

References