RackTop Systems
Threat Brief

Silent Ransom Group is stealing law firm files without ransomware

The FBI has warned twice about Silent Ransom Group, an extortion crew that talks its way into law firms by posing as IT support, then copies client files out with ordinary remote-access and file-transfer tools. Nothing gets encrypted. By the time the ransom note arrives, often within a half hour of the exfiltration, the only question left is what exactly they took.

RackTop SystemsJuly 21, 20267 min read

Key takeaways

  • The FBI issued an alert on Silent Ransom Group (also tracked as Luna Moth, Chatty Spider, and UNC3753) in May 2025 and a follow-on flash advisory in May 2026, warning that the group impersonates IT personnel to social-engineer its way into law firms.
  • The intrusion chain contains no malware. Victims are talked into remote-assist sessions, then commercial tools such as AnyDesk and Zoho Assist keep access open while WinSCP or Rclone move the files out, according to reporting from BleepingComputer based on Mandiant research.
  • There is no encryption stage at all. The take is client files: contracts, tax records, Social Security numbers, merger and acquisition documents. Reported demands run from one to eight million dollars, with data from dozens of firms already published.
  • When every tool in the chain is legitimate and the session is authorized, the reliable tell is behavioral: an account reading entire matter folders at machine speed looks nothing like a lawyer working a case.

Silent Ransom Group starts with a phone call, or an email that leads to one. An employee at a law firm receives an invoice-themed message with no attachment and no malicious link, just a number to call. The person on the other end claims to be from the firm’s own IT department and walks the employee into a remote-assist session using Microsoft Teams, Zoom, or Quick Assist. From there the group installs commercial remote-access software and begins copying files out with standard transfer utilities. According to public reporting from BleepingComputer based on Mandiant research, the campaign ran hard against legal, financial, and professional-services organizations from January through May 2026, and the FBI has now warned about the group twice: an alert in May 2025 and a flash advisory in May 2026. The second warning added a detail that would sound invented if the bureau had not put it in writing: when the remote approach fails, the group has sent people to the victim’s office in person, posing as support staff.

The group, which Mandiant also tracks as Luna Moth, Chatty Spider, and UNC3753, never encrypts anything. Ransom demands reportedly arrive within about thirty minutes of the data leaving the network, run between one and eight million dollars depending on firm size according to research from EclecticIQ, and come with a three-day deadline. Reporting in late May placed data from more than three dozen firms on the group’s leak site.

Every tool in the chain is legitimate

There is nothing for antivirus to flag here. AnyDesk, Zoho Assist, WinSCP, and Rclone are ordinary administrative software, present in thousands of well-run environments. The remote session was opened by the employee. The account doing the reading is real and authorized. A security stack tuned to catch malware and exploit traffic can watch this entire attack and log nothing unusual, because at the network and endpoint layers nothing unusual is happening.

What the attack cannot disguise is what it does to the file estate. Law firms concentrate exactly the material extortionists want, and it lives as unstructured data: client matters, deal rooms, tax and financial records, case strategy, all of it sitting on file shares reached over SMB, NFS, S3, and Web Drive. Emptying those shares means reading them, in bulk, in a way no human workday resembles.

The file system sees what the help desk scam hides

A paralegal’s account that normally touches a handful of matters suddenly enumerating and reading whole practice areas is a loud event at the storage layer, even when every upstream control stays quiet. Rclone pulls data at sustained machine throughput; a person browsing documents does not. Behavioral detection at the file system, the job Active Defense was built for, profiles what each user, host, and dataset normally does and severs the session when a bulk read departs from that baseline, while the copy is still in progress rather than after the demand letter lands.

Access scope matters just as much. Firms already think in ethical walls; attribute-based access control turns that thinking into per-operation enforcement at the file, so a receptionist’s compromised session cannot reach litigation strategy, and even a partner’s account is held to the matters it actually works. A social-engineered credential is then a bounded problem instead of a master key.

Confidentiality obligations follow the data out the door

For a law firm, the aftermath is not only a ransom decision. It is a privilege and disclosure problem: which clients, which matters, which documents. An immutable record of every read, by whom, from where, over which protocol, lets a firm answer those questions precisely instead of assuming the worst across its entire client base. Silent Ransom Group’s model leaves backups untouched and useless as leverage in either direction; there is nothing to restore, and restoring nothing un-publishes a leaked client file. The intervention window is the copy itself. Firms that can see and stop a bulk read on live data hold that window. Firms that cannot will learn what left from the extortion note.

What CIOs should put on the table now

Start with the front door this group actually uses. Help-desk and IT-support contact should be verifiable out of band: employees need a simple rule that no legitimate IT call ever asks them to open a remote session on the spot, and a number they can call back to check. Sanction a short list of remote-assist tools and block the rest through application control, so an AnyDesk or Zoho Assist install that nobody approved fails quietly. Egress filtering on file-transfer destinations raises the cost of Rclone and WinSCP runs. These steps are worth taking, and none of them is sufficient on its own; the FBI advisory describing operatives who show up in the lobby is evidence of how much persistence this group brings to getting a session opened.

So assume the session happens, and ask what it can reach. The question for the storage team is concrete: if one associate’s credential is driven by an attacker for an afternoon, how many matters, how many shares, how many years of files are exposed? If the honest answer is unknown, that is the finding. Least privilege has to be enforced at the file, where the data lives, not only at the identity provider, and access should map to the matters a person actually works. The parallel question for the SOC: would anything alert while an account reads at machine speed, and can anything act on live data in seconds, or does the first signal arrive in a report the next morning? File-activity telemetry belongs in the SOC’s feed alongside endpoint and network data, and detection at the storage layer should carry the authority to sever a session, not just log it.

Then rehearse the aftermath before it is real. The demand letter in this campaign reportedly arrives within a half hour of exfiltration, with a three-day deadline; a tabletop exercise should test whether the firm could produce a client-by-client, document-by-document account of what was read in that window. That requires a per-operation audit trail that attackers cannot edit, retained where an intruder with admin access cannot reach it. One more measurement worth making honestly: a resilience program whose main metric is restore time is not measuring anything this attack touches. Recovery answers encryption. Only detection during the read answers theft.

See data-layer defense in action

A 30-minute demo shows Active Defense stopping an attack inline, immutable recovery, and surgical rollback — mapped to your environment.

Law Firm Data Breach: Silent Ransom Group Defense | RackTop Systems