HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Silent Ransom Group Uses Fake IT‑Support Calls to Extort U.S. Law Firms

The Silent Ransom Group is leveraging invoice‑themed phishing emails followed by impersonated IT‑support phone calls to gain remote access to U.S. law firms, install legitimate RMM tools, and exfiltrate sensitive client data. The campaign highlights a low‑tech but high‑impact social‑engineering vector that threatens third‑party risk for legal‑service providers.

LiveThreat™ Intelligence · 📅 June 07, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Silent Ransom Group Uses Fake IT‑Support Calls to Extort U.S. Law Firms

What Happened – The Silent Ransom Group (aka UNC‑3753, Luna Moth, Chatty Spider) is conducting a social‑engineering campaign against U.S. law firms and professional‑services firms. Attackers start with invoice‑themed phishing emails that prompt victims to call a phone number, then impersonate IT help‑desk staff and force remote‑support sessions (Teams, Zoom, Quick Assist, etc.) to install RMM tools and exfiltrate data.

Why It Matters for TPRM

  • Legal practices store highly sensitive client, M&A, and regulatory data, making them prime extortion targets.
  • Successful intrusions can lead to rapid data theft and reputational damage, forcing third‑party vendors to manage breach notifications and regulatory fallout.
  • The tactic leverages “phone‑back” phishing, a low‑tech vector that bypasses many traditional email‑security controls.

Who Is Affected – Law firms, accounting firms, and other professional‑services organizations in the United States; downstream vendors that host or process legal data (e.g., cloud‑hosting, document‑management SaaS).

Recommended Actions

  • Review contracts for incident‑response and breach‑notification clauses with legal‑service providers.
  • Verify that vendors enforce multi‑factor authentication and least‑privilege for remote‑support tools.
  • Conduct phishing‑simulation training that includes “call‑back” scenarios and reinforce verification of IT‑support identities.

Technical Notes – Attack chain: invoice‑themed phishing email → phone call impersonating IT → remote‑support session (Teams/Zoom/Quick Assist) → installation of AnyDesk, Zoho Assist, Bomgar, or SuperOps → network foothold and data exfiltration. No known CVE exploitation; relies on social engineering and legitimate remote‑access utilities. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/silent-ransom-group-targets-law-firms-with-fake-it-support-calls/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Monitor Your Vendor Risk with LiveThreat™

Get automated breach alerts, security scorecards, and intelligence briefs when your vendors are compromised.