Silent Ransom Group

THREAT ACTOR PROFILE

Silent Ransom Group

Silent Ransom Group

Silent Ransom Group

Luna Moth

Silent Ransom Group is a financially motivated data-extortion operation active since at least 2022. It steals and publishes victim data without routinely encrypting files, and it leans on vishing, callback phishing and IT-support impersonation to get RMM tools onto targets. Its main focus is US law firms, with spillover into insurance, finance, healthcare and accounting.

Not attributed

Legal / Professional services

First seen

2022

Latest IOC

-

IP indicators

Hosts

SHA256 hashes

Posts

NAMES AND ALIASES

Silent Ransom Group, Luna Moth and UNC3753

Silent Ransom Group is tracked under several names across vendors. It maps to one entry among the extortion crews we track, and its social-engineering tradecraft overlaps with crews like Scattered Spider.

-

-

-

GROUP PROFILE

Data-theft extortion without the ransomware

Silent Ransom Group makes money through pure data-theft extortion. It skips file encryption in most intrusions, instead exfiltrating sensitive documents and threatening to publish them on a leak site to pressure victims into paying.

Our record ties it to data-theft extortion against legal and professional-services targets. Mandiant and GTIG documented a US-focused campaign that used vishing, social engineering and even in-person intrusions to reach sensitive data.

The group's access tradecraft centers on benign invoice-themed emails to prime victims, followed by calls impersonating IT staff to coerce screen-sharing and installation of legitimate RMM tools.

Facts:

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Victims reported in our records and posts:

-

-

-

-

-

ATTACK LIFECYCLE

Vishing and RMM tools into data theft

The stages below come from Silent Ransom Group and UNC3753 activity in posts we track on our IOC Hunter feed.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

MALWARE AND TOOLING

RMM abuse and fast-flux infrastructure

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

CVES EXPLOITED

Access through social engineering, not CVE exploitation

Silent Ransom Group's intrusions in our records rely on vishing, IT-support impersonation and abuse of legitimate RMM tools rather than on exploiting software vulnerabilities, so this profile does not list a confirmed exploited-CVE set. Detection should focus on unexpected RMM installs following IT-themed calls and on the group's fast-flux leak-site infrastructure.

Silent Ransom Group

IOCS FROM HUNT.IO PLATFORM

Latest IOCs

We currently track - IP indicators, - hosts, and - SHA256 hashes for Akira across - intelligence posts, with the most recent indicator dated -. The sample below is limited to indicators from the latest posts. It is not the full set.

Silent Ransom Group

Hosting Company

IPs

Date

Hosting Company

IPs

Date

144.126.202.227

LameHug exfil

06-17

Showing a sample of recent indicators

Get the complete

Silent Ransom Group

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

Silent Ransom Group

IOC set, full IP, host and hash history.

NOTABLE CAMPAIGNS

Vishing campaigns and fast-flux leak sites

Recent reporting tracks the group's extortion of US law firms.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

Showing a sample of recent indicators

Get the complete

Silent Ransom Group

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

Silent Ransom Group

IOC set, full IP, host and hash history.