⚠JUST IN: FBI IC3 released an advisory on a group known as "Silent Ransom Group"
Silent Ransom Group (SRG, Luna Moth, Chatty Spider, UNC3753), has been active since 2022, targeting finance, insurance, and healthcare companies, through social engineering attacks. Their playbook usually consists of impersonating IT helpdesk, sending phishing emails, establishing access to unauthorized systems and exporting data via legitimate remote access tools. SRG has also sent individuals in-person to victim corporations and gaining internal access that way. Group has been shifting their scopes onto US-based law firms, as of Spring 2023.
IC3 has called SRG: "Unconventional from different ransomware groups.", due to their unique nature. SRG does not follow the usual route, by relying on traditional ransomware encryption. Instead, they seek swift access to victims' systems, export the data, and extort the companies through threatening to leak the data publicly, or sell it.
Attackers call an employee to social engineer remote access; if that fails they send an operative to plug a device into the victim's machine, then trick the user into imaging/backing it up and use escalated privileges to exfiltrate data via WinSCP or a disguised Rclone.
@arch
Post #28
1.71K

- ❤ 2