Red Team

Silent Ransom Group leak exposes fake IT calls and office intruders

Leaked Luna Moth Files chats show Silent Ransom Group’s malware-free extortion: fake IT support calls and paid agents walking into law offices.

Target motif illustrating Silent Ransom Group's social engineering and physical intrusion tactics against law firms

A leaked archive of internal chats from the Russian Silent Ransom Group shows how a crew that never encrypts a file has built an extortion business on fake IT support calls and paid impostors walking into law offices. The gang now denies it was breached, but blockchain analysts say parts of the cache line up with real money movements.

What happened

In early October an unidentified source published an archive on a dedicated .onion site under the title “The Luna Moth Files”. It holds 5,692 messages, mostly in Russian, covering August 2025 to September 2026, and is attributed to the Silent Ransom Group (SRG), a data extortion outfit that other researchers label Luna Moth, Chatty Spider or Storm-0252. Researcher Tammy Harper first passed it to DataBreaches.net.

The most recent development came at the end of the week. According to Security Affairs, writing on 10 October, SRG initially agreed to an interview with DataBreaches and then insisted its systems had not been compromised. DataBreaches published a follow-up on 9 October setting out further evidence that contradicts that denial.

Chainalysis said several wallet addresses in the leak tie back to extortion payments it was already tracking, while stressing that it could not vouch for every claim in the cache. Crystal Intelligence traced the wallets named in the chats and followed funds upstream to a collection wallet that has received around 2,675 BTC over its lifetime. The gang’s own deal board claims about $207 million from 27 organisations between 3 April and 24 September 2026. Crystal says the blockchain supports a business of that size, but no wallet can be matched to any one victim’s payment. Recorded Future News counted around 50 organisations in the records, mostly law firms. Every victim name and amount in the archive is an unverified criminal claim.

The technical picture

SRG emerged in 2022 from the wreckage of Conti; its people were behind BazarCall, the callback scheme that fed access to Ryuk and Conti. Its present model needs no malware at all. Staff receive a fake invoice or a call from someone claiming to be internal IT support. The caller then talks the victim into opening a remote desktop session, uses legitimate tools to pull data out, and demands payment to keep it private. According to Security Affairs, DataBreaches matched nine of the 27 names to breach notices filed this year; one describes a fake IT caller getting a lawyer to push files to an outside Google Drive.

The more unusual element is physical. In May 2026 the FBI warned of impostors claiming to be IT staff walking into law offices and leaving with data on USB sticks. The chats put flesh on that warning. The gang recruited what it called “agents” through Russian-language job adverts for nightclub promoters, couriers and security work, with promoter roles in Miami, Orlando and New York offering $300 or more a night, then steered respondents into office intrusions. Ideas discussed included delivery uniforms to get past reception, smart glasses to film offices and kit for forging identity cards. Nothing in the archive proves those specific ruses were attempted, but in one negotiation a firm said an intruder had visited its New York office and left with files on a flash drive.

The operation was run like a sales pipeline, with victims moving through stages labelled chat, offer, contract and “gold” for paid. Payouts followed strict rules: a fresh address for every payment, one victim per wallet, and delayed cash-out through instant exchangers paying roubles to Russian bank cards, a Moscow cash broker and a Bitcoin-to-Zelle desk. Crystal found the rules broke down in practice, with one member spending two payouts in a single transaction and smaller sums for agents and forgers landing at regulated exchanges that verify customer identity. Crystal describes that as the network’s weakest point.

The chats also contain darker material, including proposals to surveil senior lawyers, kidnap executives, blackmail targets and approach a US defence contractor. There is no evidence in the archive that any of those plans was carried out.

Flow diagram of Silent Ransom Group's extortion chain from fake IT support contact through office intrusion and data theft to cash-out

Why it matters for UK organisations

None of the reporting names a UK victim, and every documented physical intrusion is in the United States. That is not a reason to relax. Large international law firms operate substantial offices in London, and the attributes that make a US firm attractive to SRG apply equally here: privileged client data, partners who fear reputational damage, and a culture in which fee earners expect IT to call them about problems.

The bigger lesson is that the attack surface here is human and physical. Endpoint detection, email filtering and patching, the controls most UK boards ask about, have limited purchase on an employee who willingly starts a remote session for a convincing caller, or on a visitor in a branded polo shirt who walks to a desk and plugs in a USB stick. Data walking out that way can still trigger UK GDPR breach obligations.

Expert view

In my experience, physical and social engineering engagements remain the cheapest way to beat a well-funded security programme. When we test reception procedures, a confident person carrying food or a laptop bag is rarely challenged. SRG has turned that into an industrial process, with recruitment funnels, conversion rates and props budgets. A group claiming nine-figure sums without writing malware has no reason to change until defenders make it harder.

The money trail is instructive too: the gang’s careful rules held only until someone got lazy. The weak point is usually the person under time pressure, whether a criminal recruiter or a junior associate taking a call from “IT” at six in the evening.

It is also worth being sceptical. The responsible reading is that the tradecraft is corroborated by the FBI’s earlier warning and by on-chain analysis, while the victim list and totals remain claims.

What to do now

  1. Lock down helpdesk identity checks. Staff should never accept an inbound call as proof that someone works for IT. Publish a rule that IT will never ask users to install remote access software or start a support session unprompted, and give staff a known internal number for verification.
  2. Control remote access tools. Under Cyber Essentials secure configuration and user access control, block unapproved remote monitoring and management tools and personal file-sharing services, and alert on new installations.
  3. Restrict removable media. Disable or tightly control USB mass storage on fee earner and partner devices, and log any exceptions.
  4. Test visitor management. Verify contractors and “IT engineers” against bookings, escort visitors beyond reception and challenge unbadged people. Commission a physical social engineering assessment if you have never had one.
  5. Train for callback phishing specifically. Use fake invoice and support call scenarios, including for partners.
  6. Prepare an extortion playbook. Agree in advance who handles contact, privilege and regulatory notification.

Bottom line

The Luna Moth Files are messy and partly unverified, but the tradecraft they describe is consistent with what the FBI has already warned about. SRG shows that a phone, a convincing script and a recruit with a fake lanyard can achieve what many malware crews cannot. UK firms should assume the playbook travels and test their people, helpdesks and front doors.

Sources