Silent Ransom Group targets law firms with fake IT support calls
Mandiant says Silent Ransom Group is targeting U.S. law firms with fake IT support calls that can lead to data theft within hours. Remote support tools help the attackers get in fast.
Intelligence analysis by GPT-5.4 Mini

The Silent Ransom Group is using invoice-themed emails and fake IT help desk calls to trick U.S. law firms into remote support sessions. Mandiant says the group then steals sensitive documents and follows up with fast, aggressive ransom demands.
A sneaky gang is pretending to be a company’s tech-help team. They trick workers into opening the door for them, then steal important papers and demand money fast, like a thief who gets inside by pretending to fix the lock.
Analysis
Attack chain
Mandiant says the Silent Ransom Group, also tracked as UNC3753, Luna Moth, and Chatty Spider, has been targeting dozens of organizations in the legal, financial, and professional services sectors between January and May 2026. The campaign starts with invoice-themed phishing emails sent from consumer email accounts. Those emails are benign on their face: they do not include malicious links or attachments, but they are meant to trigger a follow-up phone call.
How the intrusion works
After the call, attackers impersonate corporate IT staff and push the target into remote support sessions through tools such as Microsoft Teams, Zoom, Quick Assist, or Microsoft Terminal Services. During those sessions, the attackers persuade employees to install remote monitoring and management software like AnyDesk, Zoho Assist, Bomgar, or SuperOps, which gives them an initial foothold in the network. Mandiant also found phishing domains that mimic internal IT portals, using names such as -itdesk, -it, and -helpdesk.
The group also uses privnote.com to exchange links and commands during the session, which Mandiant says can leave fewer traces in browser history or corporate chat logs. Once inside, the attackers look for contracts, tax records, Social Security numbers, and merger or acquisition files, then move the data out with tools like WinSCP or Rclone.
Extortion pressure
The operation is unusually fast. Mandiant says ransom demands often arrive within 30 minutes of the attackers leaving the victim environment, and the letters give organizations three days to begin negotiations. If the victim does not respond, the attackers threaten to contact employees and clients directly to expose the breach. The FBI has also warned that the same group has used in-person data theft tactics against U.S. law firms, including attempts to image computers or secretly copy files.
Key points
- Mandiant says the Silent Ransom Group is targeting U.S. law firms and professional services organizations.
- The campaign starts with invoice-themed phishing emails, then shifts to fake IT support calls.
- Attackers use remote support tools to gain access and install remote monitoring software.
- Once inside, they search for sensitive legal and financial documents and steal them with file-transfer tools.
- Ransom demands can arrive within 30 minutes, with three-day deadlines and threats to contact clients directly.
If law firms treat invoice emails and unexpected IT support calls as warning signs, the easiest part of this attack chain becomes much harder to pull off. Stronger checks around remote support sessions and remote tools could also cut down the chance of data theft.
The group moves quickly, which leaves victims little time to notice the intrusion before documents are stolen. If firms trust the fake support call, the attackers can exfiltrate sensitive files and then pressure the organization, employees, and clients with direct extortion threats.



