Skip to main content

Hit by ransomware? Isolate affected systems now. Do not reboot or reformat.

SheMo Noransom舍末无勒

Ransomware family

Silent Ransom Group Ransomware Decryption & Data Recovery

  • Active
  • High
  • No public decryptor

Silent Ransom Group (Luna Moth, Chatty Spider, UNC3753) is a Conti-lineage crew that extorts without encrypting anything. Operators impersonate an internal IT helpdesk by phone, walk staff into a remote-access session, take documents out, then press with a clearnet leak site and calls to employees. The FBI flagged in-person intrusions with USB storage in both May 2025 and May 2026.

First seen
2022-03
File extensions
No public information
Ransom notes
No public information
Affected platforms
Windows

Family profile

File extensions
No public information
Ransom notes
No public information
Contact patterns
  • Typosquatted IT helpdesk domains shaped as `<org>-itdesk`, `<org>-it`, `<org>-helpdesk` plus a common TLD
  • Invoice-themed and follow-up extortion mail from consumer mailboxes (Gmail, Outlook), with no links or attachments
  • VoIP callback numbers and inbound "IT helpdesk" calls; early campaigns routed via call-centre numbers inside PDF invoices
  • Burn-after-reading links such as Privnote, used to hand over remote-tool installation commands
  • Clearnet leak site `business-data-leaks[.]com`, styled LEAKEDDATA DLS in extortion mail
Aliases / versions
SRG、Luna Moth、Chatty Spider、UNC3753、静默勒索组织
First seen
2022-03
Status
Active
Operational status
Actively operating
Threat level
High
Affected platforms
  • Windows
Tags
  • Extortion-only
  • Active
  • Phishing
Decryptor
No public decryptor

Decryption does not apply to this family. Silent Ransom Group never deploys an encryptor. Victim files are not renamed and do not stop opening, so there is neither a usable decryptor nor any need for one. That is precisely why the brand appears in no No More Ransom listing and in no vendor tool set.

The loss sits entirely on the confidentiality side: documents have been copied out intact, and the operators apply pressure by threatening publication on their leak site and by calling employees and clients directly. In cases like this, shopping for a decryptor is a directional error that consumes the budget and the hours that forensics, notification and credential rotation actually need.

A useful inverse test: if your files genuinely are encrypted, renamed with a new extension, or accompanied by a note dropped on disk, the incident is probably not Silent Ransom Group - it is another family, or someone leaning on the name. Re-run sample identification rather than carrying over the assumptions on this page.

Treat with caution any third party offering to "delete the stolen data" or to have leak-site pages removed. Destruction cannot be verified technically, and in practice such offers usually amount to paying the ransom and reselling it at a markup.

Latest activity

  1. Leak-site activity continued through the summer: multiple large US law firms were listed between mid-August and 4 September 2026, one for the second time in a year. Trackers record about 145 victims in total.

    Sources
  2. Halcyon warns the crew has used on-site physical intrusion since April 2025, posing as IT to attach storage and exploiting the gap between cyber and physical security. One law firm reportedly paid eight figures.

    Sources
  3. FBI FLASH confirms Silent Ransom Group (Luna Moth) impersonates IT staff, and newly reports in-person intrusion: when remote persuasion fails, an operative visits the office and copies data to removable storage.

    Sources

Overview

Silent Ransom Group has been active since at least March 2022, coinciding with the collapse of the Conti syndicate. Its operators had previously run BazarCall-style callback phishing to hand initial access to Ryuk and Conti; once Conti shut down they broke away, dropped the encryption payload entirely and kept only data theft and exposure extortion. Note that while Mandiant and others place the crew in the Conti lineage, Unit 42's 2022 reporting explicitly declined to confirm that tie. Mandiant tracks the same cluster as UNC3753 and CrowdStrike calls it Chatty Spider; FBI advisories list SRG, Luna Moth, Chatty Spider and UNC3753 together as one actor.

The tradecraft has shifted three times.

  • 2022 to early 2025. Callback phishing built on fake subscription renewals and invoices; the mail carried only a PDF and a call-centre number, and the FBI notes the "subscription fees" were deliberately small so victims were less likely to grow suspicious.
  • From spring 2025. Calling staff directly while posing as the victim's own IT helpdesk, using "a security issue" or "a data migration" as the pretext to open a screen-sharing session. Targets are not executives but employees at every level listed on the company website.
  • From April 2025, first reported by the FBI in May 2025 and restated in May 2026. Where remote social engineering fails, the crew sends someone to the victim's office claiming they must "image the device" or "create local backups", and copies data straight to removable storage.

Scale and targeting. Ransomware.live records roughly 145 organisations named on the clearnet leak site, about 114 of them in the United States - close to eight in ten - with professional services (law firms foremost) ahead of financial services. FBI advisories add insurance and healthcare victims and state that the crew has consistently targeted US law firms since spring 2023. Between January and May 2026 Mandiant traced dozens of US professional, legal and financial services organisations breached in a single wave. The FBI issued two dedicated products on the same crew within a year - a PIN on 23 May 2025 and a FLASH on 26 May 2026 - which is unusual. As of early September 2026 the leak site was still being updated, most recently on 4 September.

Public reporting has referred to a victim law firm paying a large suppression sum, but no figure has been confirmed by the victim or by law enforcement, so this page does not adopt one. For scale, reporting around the FBI's 2025 advisory put demands in the single-digit millions - not the double-digit range.

A naming note. SRG is not a "ransomware virus" and has no encryptor sample to analyse. Its helpdesk-impersonation playbook resembles Scattered Spider's, but they are different groups and their indicators should not be applied interchangeably.

How to identify it

There is no extension and no note file on disk, so identifying this family by its suffix does not apply. Files still open normally, and most victims only learn what happened when the extortion mail arrives. Six verifiable surfaces remain:

  • Mail. Invoice or subscription-themed messages from consumer mailboxes, short and sometimes misspelt, carrying no links and no attachments; their only job is to set up the call that follows.
  • Domains. Helpdesk lookalikes closely matching the company name, shaped as <org>-itdesk or <org>-helpdesk.
  • Endpoint. Unauthorised remote-tool sessions appearing within a short window - AnyDesk, Zoho Assist, RustDesk, Bomgar, SuperOps, Syncro, Splashtop, Atera - or abuse of Quick Assist, Teams and Terminal Services. The characteristic install is curl fetching an MSI followed by msiexec /quiet.
  • Exfiltration. Portable WinSCP, renamed or hidden Rclone, uploads to Google Drive, OneDrive and similar cloud storage, and files mailed out from the employee's own mailbox; sustained outbound traffic on port 22 is a strong signal.
  • Extortion. Mail subjects along the lines of "<Company> has lost confidential data of their clients", a three-day deadline, threats to notify staff and clients and to publish on the leak site, then phone pressure.
  • Physical. A visitor claiming to be IT support asks to "image the device" or "create local backups" and plugs in removable storage.

Because the chain uses legitimate tooling and drops no conventional malware, static EDR detection is poor. What works is a composite signal: an unexpected RMM install, plus bulk document access in a short window, plus heavy egress.

Infection vectors

SRG's entry point is people, not vulnerabilities. It barely bothers with privilege escalation or estate-wide lateral movement: one ordinary employee's endpoint with access to the document store is enough.

Voice phishing is the main line. A harmless invoice-themed email sets up the topic, then the "IT helpdesk" calls, citing a security alert or a data migration, and asks the employee to join a screen share. The session tools are ones the company already uses - Teams, Zoom, Quick Assist, Terminal Services - so nothing looks out of place; one documented intrusion involved five calls with the same target over three days. Once trust is established, installation commands arrive through a burn-after-reading link such as Privnote, landing an AnyDesk, Zoho Assist, Bomgar or SuperOps agent as a stable channel.

One route around endpoint control deserves separate attention. Operators open the session on the employee's personal laptop, then use that unmanaged BYOD device to reach the corporate Windows 365 or Citrix virtual desktop, stepping past the application controls and auditing that live on company-owned endpoints.

The physical vector appeared in 2025 and was restated by the FBI in 2026. Where remote persuasion fails, the crew sends someone to the office, claims the device needs imaging, gains hands-on access and copies data to removable storage. The tactic exploits the gap between cybersecurity and physical security: colleagues rarely verify a work order, and IT never learns anyone visited.

The tempo is fast. From first contact to exfiltration and extortion mail the chain often completes inside one business day; searching, staging and transfer have been observed finishing in under an hour, with the extortion mail sent within thirty minutes. A rhythm of "raise it at next week's security meeting" cannot keep up.

Encryption behavior

SRG does not encrypt anything, so this section covers what it actually does: targeted search and bulk transfer. (An associated cluster deployed a LOCKBIT.BLACK payload back in 2022; the crew has since moved entirely to theft-only operations.)

Search. After landing on an endpoint the operator enumerates local directories, mapped network drives and active OneDrive folders. In law-firm intrusions they use the keyword search built into document systems such as iManage to find sensitive matters directly - all under the victim employee's own legitimate permissions, so the audit log simply shows that person browsing files. Target data clusters around W-2, W-9 and 1099 tax forms, audit files, client agreements and HR material containing Social Security numbers; for law firms what leaves is typically matter material covered by attorney-client privilege.

Staging and transfer. Files are collected into the user's Downloads folder or Roaming profile path, then take one of three routes: drag-and-drop upload into attacker-controlled consumer file sharing accounts, with folders renamed to the victim's brand; SFTP transfer with portable WinSCP or Rclone, the fallback when browser uploads are blocked; or mailing files out from the victim's own mailbox. Volumes range from one or two gigabytes to hundreds - one documented case moved 1.7 GB out of OneDrive, then a further 14.4 GB by WinSCP from a virtual desktop session.

What this means for defenders. There is no encryption process, no shadow-copy deletion and no service stoppage, so conventional ransomware behaviour rules never fire. The monitoring that works sits on the data and network side: bulk-download alerts in document systems, unusual SFTP and cloud storage API traffic, and unapproved RMM installation events.

Assess before you act

Recoverability assessment

There is nothing to "recover" here: the data never left your systems, it was merely copied. The path is therefore rewritten as leak impact assessment and containment, in five layers of priority.

1) Decryption and file repair: not applicable. With no encryptor there is no decryptor and no structural repair to attempt. If files genuinely are encrypted, the attribution is wrong and family identification should be redone immediately.

2) Bounding the exfiltration scope and window - the top priority. Forensics must cover remote-tool session logs and install times, curl and msiexec artefacts, WinSCP and Rclone execution and leftover configuration, browser upload history, egress on port 22 and to cloud storage APIs, bulk search and download auditing in iManage or SharePoint, and mailbox send and auto-forward rules. The goal is a defensible statement of which matters left, how much and when - not a vague "possible exposure".

3) Data classification and notification duties. Segment what was taken - personal data, client material under NDA, matter files covered by attorney-client privilege, trade secrets - then set the scope and deadlines for notifying regulators, clients and staff, and assess differing local rules where operations cross borders. This track runs in parallel with legal and compliance, not after them.

4) Rotating credentials, sessions and trust. Resetting the password is only the start: re-enrol MFA, revoke OAuth tokens and long-lived sessions, rotate VPN certificates and API keys, and extend all of it to employee BYOD devices and virtual desktop profiles. The intruder entered as a legitimate user; leaving credentials untouched leaves the door open.

5) Persistence removal and device integrity. Uninstall unauthorised RMM agents and clean their services, scheduled tasks and autoruns; verify the integrity of any endpoint that was remotely operated or had removable storage attached, rebuilding where warranted. This crew enters through people and legitimate tooling, so any credential or persistence left uncleaned keeps the same route open.

We do not pay ransoms, do not negotiate, and give no assurance that "the data has been deleted" - that claim cannot be verified technically.

Our response plan

Hit by Silent Ransom Group ransomware? What to do

  1. Containment and session preservation

    Cut the remotely operated endpoint off from the internet and the internal network, but do not power it off, rebuild it, or uninstall the suspicious remote tool - uninstalling takes the session records and leftover configuration with it. Image memory and disk on that host first, and export remote-tool server-side logs, edge and VPN logs, mail gateway records, and access auditing from document systems such as iManage, SharePoint and file servers. Preserve the extortion mail in full including headers, call records, captures of the lookalike domain and of the leak-site page. Where a physical intrusion is suspected, pull door-access and CCTV records and the visitor log, and quarantine any device that was physically touched.

  2. Attribution check and kill-chain reconstruction

    SRG offers no extension or note to match, so this step is verification rather than template matching. Cross-check four evidence classes: registration and resolution characteristics of the lookalike helpdesk domain, the brand of remote tool deployed and the shape of its install command, artefacts from exfiltration tooling (portable WinSCP, Rclone, cloud storage APIs), and the subject structure and deadline wording of the extortion mail. Confirm too that this is not someone leaning on a known name - empty-handed extortion under a borrowed brand has become common. Then reconstruct the full chain: which mail set it up, which call succeeded, which device was driven remotely, whether BYOD was used to reach the virtual desktop, and whether there was an in-person component.

  3. Exfiltration scope and leak impact assessment

    Triangulate egress traffic, document-system auditing and exfiltration-tool artefacts to bound the directory inventory, data volume and time window, then validate it against the samples the operators showed in their extortion mail. Classify what was taken: personal data, client confidential material, privileged matter files, trade secrets. Deliver a written assessment naming the regulatory notification duties, the scope of client and employee disclosure, the contractual exposure, and the material an insurance claim will require. That assessment is the single factual basis for all external communication and must be finished before anything is said publicly.

  4. Credential rotation and persistence removal

    Work identity-first: reset affected account passwords and re-enrol MFA, revoke OAuth grants and long-lived session tokens, rotate VPN certificates, API keys and service-account credentials, and inspect and clear mailbox auto-forwarding and delegation rules. On endpoints, uninstall unauthorised RMM agents, clean their services, scheduled tasks and autoruns, and check for a second channel; decide the rebuild scope for remotely driven or physically touched devices from the forensic findings. In parallel, block unapproved remote-tool installation and execution estate-wide, and put conditional access in front of the path from employee BYOD devices into the virtual desktop estate.

  5. Hardening, process change and handover

    Against an attack whose entry point is people, hardening cannot stop at technology. Technical: allowlist remote tools and alert on anything else, enable bulk search and download alerting in document systems, monitor egress for anomalous SFTP and cloud storage API transfers, restrict access to the corporate desktop estate from non-corporate devices, and enforce MFA on critical repositories. Process: build two-way verification for the IT helpdesk so staff can call back through a known internal channel, require a work order and an escort for any on-site technician, and disable external USB read/write by default. People: run drills specific to voice phishing and "helpdesk calling" scenarios rather than generic phishing-email training. Close with an incident report and a formal handover checklist.

Risk warning

What not to do

  • Do not downgrade the incident because "nothing was encrypted and systems still work". SRG's entire leverage is the documents already taken, and uninterrupted operations are exactly why these cases get underestimated.
  • Do not uninstall the suspicious remote tool on the affected endpoint or rush to rebuild it. Once session logs, install artefacts and exfiltration-tool configuration are gone, the scope of what left cannot be evidenced, and both notification and insurance claims lose their basis.
  • Do not reply to the extortion mail or call the operators "just to see what they want". Unplanned contact reveals how sensitive you consider the data and how fast you decide, which is used directly to raise the price, and may trigger early outreach to your clients and staff.
  • Do not stop at resetting the one compromised password. The intruder came in as a legitimate user, so MFA re-enrolment, OAuth token revocation, VPN certificate and API key rotation, and a review of mailbox forwarding rules are all required.
  • Do not let anyone claiming to be IT - on the phone or at the door - take control of an endpoint, start a screen share or attach removable storage before the work order is verified. This is currently the single control that reliably stops this crew.
  • Do not trust third parties promising that stolen data "will be deleted" or that leak-site pages can be removed. Deletion cannot be verified technically, and such offers usually amount to reselling a paid ransom; the FBI also notes the crew is inconsistent in its use of its own leak site, so neither publication nor removal follows from payment.

Emergency response

Data already encrypted? Stop and let an engineer look first

We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.

Related scenarios

Related industries

Similar families

FAQ

Silent Ransom Group Frequently asked questions

  • Does Silent Ransom Group encrypt files? Nothing of ours is encrypted - is this still a ransomware incident?

    No, it does not - and yes, this is a full extortion incident, at no lower priority than an encryption attack.

    SRG never deploys an encryptor. Extensions are unchanged, files open normally and systems keep running, which is why many organisations call it a false alarm or ordinary phishing in the first few hours and lose the forensic window. Its leverage is the documents already copied out: after the three-day extortion mail come calls to employees, outreach to your clients and partners, and publication on a clearnet leak site.

    For law firms and accountancies, whose business rests on confidentiality, the client-relationship and professional risk from disclosure usually exceeds a few days of downtime. These cases still demand immediate containment and forensics, a bounded exfiltration scope, notification duties met, and credentials rotated estate-wide.

  • Are Luna Moth, Chatty Spider, UNC3753 and Silent Ransom Group the same crew?

    Yes - these are different vendor names for one cluster, and the intelligence can be merged.

    • Silent Ransom Group / SRG - the name used in FBI advisories and by the crew itself.
    • Luna Moth - the label most common in vendor reporting such as Palo Alto Unit 42, and in the press.
    • Chatty Spider - CrowdStrike's naming scheme.
    • UNC3753 - the uncategorised cluster number used by Mandiant and Google Threat Intelligence.

    Two things do need separating. First, SRG resembles Scattered Spider in its IT-helpdesk impersonation but is a different group, so indicators should not be applied interchangeably. Second, the crew was linked to LOCKBIT.BLACK deployment back in 2022 yet now runs theft-only operations - do not respond to it as if it were LockBit.

  • Someone from the "IT helpdesk" calls asking us to install AnyDesk or share the screen with Quick Assist. How do we tell quickly?

    One rule you can act on immediately: hang up and call back through an internal channel you already know. Never use the number, link or QR code the caller supplies.

    High-value warning signs:

    • An invoice or subscription-renewal email arrives around the same time with no links and no attachments, short and sometimes misspelt.
    • The helpdesk address they give closely matches your domain with an added suffix, such as <org>-itdesk or <org>-helpdesk.
    • Installation commands are handed over through a burn-after-reading link such as Privnote.
    • You are asked to work on a personal laptop rather than a corporate device, then to sign in to the corporate virtual desktop from it.
    • Urgency is stressed, completion is demanded on the call, and you are discouraged from checking with colleagues.

    The organisational counterpart is two-way helpdesk verification: genuine IT will never object to an employee calling back via the internal directory. Writing that into policy and drilling it is more effective than any detection rule.

  • Someone turns up at our office claiming to be IT support and wants to "image the device for backup". What now?

    This is the tactic the FBI specifically flagged in May 2025 and again in May 2026 - treat it as a suspected incident.

    When remote social engineering fails, SRG sends someone to the victim's office, claims the device needs imaging or a local backup, gains hands-on access and copies data straight to a USB stick or external drive. It exploits the gap between cybersecurity and physical security: reception and colleagues do not verify work orders by default, and IT never learns anyone came.

    On-site handling:

    • Verify before admitting. Ask for a work order number and have an employee confirm it with IT through an internal channel, not the number the visitor provides.
    • Escort throughout. No external technician touches an endpoint unaccompanied.
    • Refuse removable storage. Legitimate backup or imaging work does not require plugging in a drive the visitor brought.
    • Record either way. Log the visitor, time and devices involved regardless of the outcome, and pull door-access and CCTV records.

    If access already happened, start data-breach response immediately, quarantine the device and preserve evidence - do not rebuild it first.

  • We are already named on the leak site - will paying take it down? And should organisations in China be concerned?

    On paying: we do not pay ransoms and do not negotiate. Technically, payment buys nothing verifiable - whether the data was really deleted cannot be checked, and neither can whether copies already sit elsewhere. The FBI notes the crew is inconsistent in its use of its own leak site, so there is no dependable link between paying and a page coming down. What actually reduces loss is establishing exactly what left, then completing regulatory notification and client communication on your own terms before the operators publish.

    On geography: close to eight in ten of the victims named on this crew's leak site are in the United States, most of them law firms and similar professional services; there is little public record of organisations in China being named directly. Two caveats matter. Chinese firms with US offices, or serving US clients in legal, tax and M&A work, fit the target profile. And the tradecraft spreads - IT-helpdesk voice phishing and lookalike helpdesk domains are now a shared entry route across several crews, so the practical exposure is the playbook rather than this particular brand.

    The sensible investment is therefore in controls that generalise: two-way helpdesk verification, remote-tool allowlisting, bulk-download alerting in document systems, and a work-order-plus-escort rule for on-site technical support.