
SILENT Ransom Group, also tracked as UNC3753, has launched a vishing campaign aimed at US law firms, using fake invoice emails and bogus IT support calls to steal sensitive data for extortion according to Google’s threat intelligence team. The tactic puts confidential client information at risk and highlights a growing reliance on social engineering rather than malware exploits.
The attack begins with a harmless-looking email that mentions an overdue invoice, prompting the recipient to expect a follow‑up call as reported by securityonline. When the call arrives, an attacker poses as IT staff and convinces the target to start a screen‑sharing session. During that session the victim is guided to install remote management software such as AnyDesk or TeamViewer, which gives the intruders full access to the workstation.
Between January and May 2026 the group carried out dozens of intrusions across the legal and financial sectors, often exfiltrating files within minutes of gaining access per Dark Reading. Tools like WinSCP and Rclone have been observed moving data to external servers before a ransom note is delivered. The campaign is linked to the threat clusters UNC3753 and Luna Moth, both known for financially motivated extortion.
In addition to phone‑based tricks, the gang has been seen visiting offices in person to plug USB devices into computers under the guise of hardware upgrades as noted by The Hacker News. The FBI has issued a warning advising firms to verify any unsolicited IT request through independent channels according to Infosecurity Magazine. These developments show how threat actors are blending traditional social engineering with physical proximity to bypass technical controls.
Organisations should refresh user training to include vishing scenarios, emphasizing that legitimate IT teams never ask for passwords or remote access via unsolicited calls. Enforcing multi‑factor authentication on all remote‑access solutions reduces the value of stolen credentials. Monitoring network logs for unexpected outbound connections to unfamiliar IP addresses can help spot data‑exfiltration attempts early.
Email gateways ought to be configured to block messages that contain invoice themes combined with urgent language, a common lure in this campaign. Applying the principle of least privilege limits what an attacker can do even if they manage to install a remote tool. Finally, incident response plans should be updated to cover extortion scenarios, ensuring that legal, PR and technical teams can coordinate a swift response as outlined in the FBI’s CSA.