UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign
Google says UNC3753 used vishing, screen-sharing, and in-person office intrusions to steal sensitive data from U.S. firms and extort them.
Intelligence analysis by GPT-5.4 Mini

Google Mandiant and GTIG link UNC3753 to a fast-moving extortion campaign against U.S. professional, legal, and financial services. The group relied on phone-based social engineering, remote access tools, and in some cases physical access to offices to steal data and pressure victims within hours.
UNC3753 tricked workers by pretending to be IT helpers, then used calls, screen-sharing, and sometimes real office visits to grab files. It was like a thief wearing a repair badge and asking to borrow the house key, then leaving with the valuables.
Analysis
What happened
Google Mandiant and Google Threat Intelligence Group say UNC3753 targeted dozens of U.S. organizations from January through May 2026. The campaign focused on professional, legal, and financial services and used voice phishing, fake IT support calls, and benign-looking invoice or migration emails to build trust and get victims to join screen-sharing sessions.
How the intrusion worked
Once contact was established, the attackers persuaded victims to install legitimate remote monitoring and remote desktop tools such as AnyDesk, Bomgar, SuperOps RMM, and Zoho Assist. In some cases, they guided victims to do the work themselves; in others, they searched systems directly for files to steal. The stolen data included legal agreements, personal data, financial records, tax and audit files, client agreements, and Social Security numbers.
The article says the operation also escalated beyond remote access. In some incidents, attackers physically entered offices while posing as IT technicians and used removable USB media or external drives to copy data. Google says this echoes an FBI advisory on in-person intrusion tactics.
Why the group is dangerous
UNC3753 has tactical overlap with UNC2686 and is assessed to be an offshoot of the Conti ecosystem. Google says it has used ransomware in the past, but since 2022 it has mainly run extortion-only campaigns. Victims typically received ransom demands within 30 minutes of the attackers leaving the environment, with a three-day deadline and threats to contact employees, clients, and publish the data on a leak site.
The core lesson is that technical controls alone are not enough when attackers can use social engineering to make users open the door for them.
Key points
- Google links the campaign to UNC3753, also known as Chatty Spider, Luna Moth, and Silent Ransom Group.
- The attackers used vishing, fake IT support calls, and invoice-themed emails to get screen-sharing access and install remote tools.
- Some incidents involved physical office intrusions, with attackers posing as technicians and copying data to USB or external drives.
- Stolen data included legal agreements, PII, financial records, tax files, audit material, and SSNs.
- Victims were reportedly extorted quickly, often within 30 minutes of the attackers leaving the environment.
The reporting gives defenders a clear picture of the playbook, including the lure types, remote tools, and physical intrusion step. That can help security teams train staff, tighten help-desk verification, and block suspicious use of remote access software before data leaves the network. The FBI and Google attribution may also help organizations recognize the campaign faster.
The campaign shows that attackers can bypass strong technical defenses by talking people into cooperating, which makes detection and prevention harder. Because the group can move from initial contact to extortion within a single business day, victims may have very little time to contain damage once the call starts.



