← All actors

Silent Ransom Group

Aliases: SRG, Luna Moth, Chatty Spider, UNC3753

Source profile review date: 2026-06-21

Added to the source registry: 2025-05-06 · Source snapshot: 2026-09-15

Source metadata is not independently verified. The registry date is not necessarily the first attack date. Source synopses are translated automatically where needed; the feed may contain outdated assessments.

Research status: Existing researched dossier

This dossier separates actor-specific source information from general defensive analysis. Recommendations and investigation questions are not additional claims about the actor. Public evidence remains limited where explicitly stated.

Locally generated translation; linguistic review is still pending.

Executive summary

Silent Ransom Group mainly uses callback phishing and social engineering to abuse support or management relationships and steal data without classical encryption.

Silent Ransom Group is important because the actor shows that ransomware weapon is also about helpdesks, remote support, SaaS data and human-focused controls. The attack often looks like a normal support interaction.

Latest five known victim claims

Loading stored claims…

    These are public claims attributed to the group, not independently confirmed breaches. Dates indicate publication or discovery, not necessarily the attack date.

    Management summary

    Silent Ransom Group is not a classic ransomware group that always uses encryption. The core of the threat is social engineering, callback phishing, remote support abuse and data diode. Victims are misled to contact or give access themselves, after which the actor collects and extorts data.

    The risk for organizations is in confidence. Helpdesks, employees, suppliers and remote support tools are used as input. If a employee is convinced to install a tool, start a session or login while the actor is watching, the attack may remain outside traditional malware detection.

    For defense, this means awareness is not enough. Organisations need to have technical brakes on remote support, SaaS downloads, large exports, personal cloud uploads, new inbox rules and data movement from workstations.

    Grouping and development

    Silent Ransom Group is linked by several suppliers to names such as Luna Moth, Chatty Spider or UNC3753. The group became known by callback phishing: victims receive a decoy email about a subscription or invoice and then call themselves a number that is managed by the actor.

    In the conversation, the actor convinces the victim to install remote support software or start a session. After that, access is used to search for files, access mailboxes, open cloud storage or further abuse of credentials. The pressure comes later via stolen data extortion.

    The group shows why modern extortion does not always require malware. An attack can consist entirely of convincing communication, valid user actions and legitimate tools that make behavioral detection and process control important.

    Operation and attack chain

    The chain often starts with an email suggesting an urgent financial problem: subscription, extension, payment or support case. The mail does not necessarily contain malware; the purpose is that the recipient calls. As a result many technical email filters pass through the first step.

    The actor may pose as support officer, billing department or security team during the phone call. The victim is asked to install remote support, open a browser, log in or show files. The actor subsequently tries to collect data or gain further access.

    Many used defense signals are in endpoint and SaaS behavior: installation or launch of remote support tools, new downloads from SharePoint/OneDrive/Google Drive, file compression, upload to external storage, access to personal mailboxes and deviant browser downloads.

    The extortion phase is about evidence of data aideft. Because there is often no encryption, an organization can underestimate the threat. It is precisely then that fast log analysis is needed: which data has been viewed or downloaded, which cloud locations have been accessed, which tools have been started and which accounts may have been shared?

    Known IOCs and artifacts

    The most important artifacts are callback phishing mails, phone numbers in locator messages, remote support installations, session logs, browser history, downloads, zip or archive files, cloud sync activity and extortion communication.

    Specific hashes are less important than tool and session behavior. Legitime remote tools can be AnyDesk, ScreenConnect, TeamViewer or similar products. Not every installation is malicious; the combination with an unexpected phone call and data movement makes it suspicious.

    For mail security, it is important to treat messages without payload as dangerous when they contain callback loops. Telephone numbers, billing language, urgency and external senders can serve as detection features.

    Victim pattern and lessons

    Silent Ransom Group focuses on organisations where employees have access to usable data and where remote support is socially credible. Legal services, financial administration, care, professional services and education can be attractive, but the technology is widely applicable.

    The lesson is that a user sometimes does not make a mistake by clicking on a malware link, but by trusting a convincing conversation. Therefore processes should help employees: clear rules for external support, forbidden on unauthorized remote tools and simple escalation in suspicious phone calls.

    A second lesson is that SaaS logging should be central. If the actor downloads data from cloud storage via a workstation, security teams must be able to see it without depending on the endpoint alone.

    How to arm yourself

    Block or manage remote support tools via allowlisting. Allow only approved tools, log sessions and make sure that ordinary users cannot install new remote control software without approval.

    Train staff specifically on callback phishing. Show that an email without attachment can be dangerous when the employee's goal is to call. Make reporting low-threshold and without any guilt.

    Monitor cloud data on bulk downloads, new external shares, ZIP- creation, personal storage and downloads shortly after remote support activity. Connect this to mail and phone signals to make the chain visible.

    Identity, naming and attribution

    For Silent Ransom Group, the operational starting point is an exact identity match. The local dossier records the following names or aliases: SRG, Luna Moth, Chatty Spider, UNC3753. An alias is a search aid, not independent evidence of shared operators. Similar names, reused logos and the same extortion vocabulary cannot establish a relationship between groups. Analysts should retain the original spelling of a claim and distinguish the publisher, malware family and suspected intrusion operator. Those roles can belong to different people. This prevents an incident being assigned to the wrong group simply because a filename or public post resembles an earlier case. Any proposed relationship needs its own dated, attributable source.

    Indicators of compromise (IOCs)

    Indicators are historical observations, not proof of a current infection. Validate source, age and context before hunting or blocking; legitimate administrative tools can produce false positives.

    TypeValueSourceContext
    tacticcallback phishingCISA / vendor reporting on Luna Moth and SRGPrimary initial social engineering method.
    toolinglegitimate remote support toolspublic Luna Moth reportingTool Name Different; Detect Unauthorized Use.
    behaviordata theft without encryptionpublic SRG reportingExtortion based on stolen data.

    Sources

    Evidence and limitations

    Attribution describes the source assessment, not a verified identity. A leak-site listing alone does not prove encryption, data theft, a particular vulnerability or an affiliate relationship. Missing information is left explicit.