DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:13:27ZSOURCES: 14CRITICAL: 30
⚠ ACTIVE ALERTS
@FalconFeedsio CRITICAL — 🚨 Ransomware Alert: The Gentlemen RaaS group continues active DLS postings. Now at 478… /// @DarkWebInformer CRITICAL — 🚨 ServiceNow discloses June 5 security update tied to anomalous activity — KB3067321.… /// @MsftSecIntel CRITICAL — MSTIC analysis of The Gentlemen ransomware (tracked internally): self-propagating… /// @GossiTheDog CRITICAL — ServiceNow KB3067321 situation is worse than the vendor comms suggest. Advisory was gated… /// @AlvieriD CRITICAL — The '340M OnlyFans' listing on the leak forum is a compiled corpus — seller confirmed to…
30Critical Threats
15Active CVEs
1IOCs Tracked
14New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // SILENT-RANSOM-GROUPFIRST SEEN: MAR 2022

SILENT RANSOM GROUP

ALSO KNOWN AS: Luna Moth, Chatty Spider, UNC3753, SRG
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Russia-linked (post-Conti ecosystem spinoff, March 2022)
ATTRIBUTION:ORGANIZED CRIME
STATUS:ACTIVE
FIRST OBSERVED:MAR 2022
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL62/100
RESOURCES62/100
PERSISTENCE65/100
STEALTH57/100
IMPACT71/100

A Russia-linked extortion group that spun off from the Conti post-shutdown ecosystem in 2022 and has now escalated to a historically unprecedented physical intrusion tactic: sending operatives in person to victim law firm offices, disguised as IT support staff, to insert USB drives and exfiltrate data directly. The FBI issued a FLASH-severity alert (FLASH-20260526-01) on May 26, 2026 — the highest-urgency classification — detailing this active Spring 2026 development. SRG deploys no malware or encryption, leaving minimal forensic artifacts and defeating most EDR tooling; 38+ firms have had data publicly posted and total attack count exceeds 100 confirmed incidents.

Financial extortion via pure data-theft and public disclosure threats, no ransomware encryption deployed; primary focus on attorney-client privileged data at US law firms

T1566 Callback Phishing (subscription billing lures), T1598.004 Vishing (IT impersonation over phone), Physical Intrusion (in-person USB/HDD insertion — Spring 2026 escalation), T1219 Remote Desktop Session hijacking (AnyDesk, Zoho Assist, legitimate RMM tools), T1048 Exfiltration via WinSCP / hidden Rclone, T1567 Exfiltration to OneDrive/Google Drive, T1078 Valid Account abuse, T1657 Pure data-theft extortion (no encryption), Victim employee/client harassment calls post-exfiltration

LEGAL
INSURANCE
FINANCE
HEALTHCARE

Public clearnet leak site: business-data-leaks[.]com; lookalike IT helpdesk/support portal domains registered per campaign; WinSCP and Rclone for exfiltration; AnyDesk and Zoho Assist for remote access; physical operatives with removable USB/HDD media (Spring 2026 escalation); no custom malware — entirely LOTL and social engineering

FILE DATE: SPR 2023
US Law Firm Callback Phishing Campaign
Initiated sustained, industrialized callback phishing campaign against US law firms using fake subscription billing emails directing victims to call SRG-controlled numbers.
FILE DATE: JAN 2026
Orrick, Herrington & Sutcliffe Data Leak
Data from Orrick, Herrington & Sutcliffe (>$1.5B revenue, 25+ global offices) █████████████████████ firm declined ransom; Jones Day and Wood Smith Henning & Berman similarly impacted in Q1 2026.
FILE DATE: MAY 2026
Physical USB Intrusion — FBI FLASH Alert
FBI issued FLASH-20260526-01 warning of SRG operatives physically entering law firm offices impersonating IT staff to insert USB drives; active Spring 2026 escalation with 38+ DLS postings and 100+ total confirmed attacks.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn