UNC3753 Targets US Law Firms With Vishing, RMM Tools, and Physical Intrusions


UNC3753 is targeting U.S. law firms and other professional services organizations in a fast-moving data theft and extortion campaign that relies on phone calls, remote access tools, and in some cases in-person office visits.

The financially motivated group, also known as Luna Moth, Chatty Spider, and Silent Ransom Group, has been active since at least 2022. In its latest wave, the group targeted organizations across legal, professional, and financial services between January and May 2026, according to a Google Cloud threat intelligence report.

The campaign stands out because it avoids traditional malware in many cases. Instead, attackers call employees while pretending to be internal IT staff, convince them to join screen-sharing sessions, and push them into installing legitimate remote monitoring and management tools.

UNC3753 moves from phone call to data theft within hours

Googleโ€™s Mandiant and Google Threat Intelligence Group said some UNC3753 intrusions moved from first contact to data theft and extortion within a single business day. In recent cases, file searching, staging, and exfiltration began in under an hour.

The group usually starts with a simple invoice-themed email from a consumer email account. These messages often contain no malicious links or attachments. Their goal is to create concern, so the target becomes more likely to answer a follow-up call from someone claiming to work for IT support.

This tactic maps closely to vishing, where attackers use voice calls to manipulate victims. MITRE ATT&CK describes spearphishing voice as the use of phone calls to obtain sensitive information, often while posing as a trusted source such as technical support.

StageWhat UNC3753 doesWhy it works
Pretext emailSends a harmless-looking invoice or IT-themed message.The email avoids malicious links and attachments.
Vishing callCalls the employee while posing as IT or security staff.The attacker builds trust through direct conversation.
Screen-sharing sessionGuides the victim into joining a remote support session.The victim performs actions that security tools may not block.
RMM installationPushes AnyDesk, Bomgar, Zoho Assist, or SuperOps RMM.These tools can look legitimate in business environments.
Data theftSearches, stages, and exfiltrates sensitive files.The group focuses on documents valuable for extortion.

Attackers abuse legitimate remote support software

Once the target joins a session, UNC3753 uses screen-sharing tools and remote access utilities to bypass normal perimeter security. Google observed the group using Zoom, Microsoft Teams, Microsoft Terminal Services, Quick Assist, AnyDesk, Bomgar, Zoho Assist, and a SuperOps RMM agent in different incidents.

The group also uses Privnote to send installation links or commands. Since Privnote messages disappear after they are opened, this can reduce evidence left in chat logs, browser history, or copied messages.

Remote monitoring and management software has legitimate business uses, but attackers can abuse it for interactive access. MITRE ATT&CK lists remote access software as a technique where adversaries use legitimate support tools to control target systems or maintain access.

BYOD devices and virtual desktops expand the attack path

Some UNC3753 intrusions began on personal laptops used for work. After gaining control of a Bring Your Own Device endpoint, attackers accessed corporate virtual desktop environments through Windows 365 or Citrix clients.

From there, they searched corporate file stores, mapped network drives, OneDrive folders, and legal document management systems. Google said the group searched iManage repositories for files containing tax records, W-2, W-9 and 1099 forms, corporate agreements, audit records, and Social Security numbers.

The attackers then staged files in folders the victim could access, often inside Downloads or profile paths. In several cases, they exfiltrated files by using portable WinSCP, Rclone, cloud storage uploads, or direct uploads from the victimโ€™s browser.

  • Common tools observed include AnyDesk, Bomgar, Zoho Assist, SuperOps RMM, WinSCP, and Rclone.
  • Common lures include invoice messages, IT support calls, security checks, and data migration claims.
  • Common targets include legal agreements, tax documents, client files, financial records, and personal information.
  • Common access paths include screen-sharing sessions, BYOD laptops, VDI environments, and cloud storage accounts.

The group also uses physical office intrusions

The FBI warned in a May 2026 Cyber FLASH alert that Silent Ransom Group is targeting law firms through IT-themed social engineering calls and phishing emails. The FBI advisory said actors may send someone in person to a victimโ€™s office if remote social engineering fails.

In those incidents, the person claims to be IT support and says they need to image a device or create a backup. Once they get access to the computer, they try to copy data to a USB drive or external hard drive.

UNC3753 attack lifecycle (Source – Google Cloud)

Google said it assessed these physical intrusion attempts as likely linked to UNC3753 based on structural, timeline, and targeting overlaps. The shift is important because it moves the threat beyond email security and endpoint monitoring into front-desk procedures, visitor controls, and removable media policies.

Risk areaObserved behaviorRecommended control
IT impersonationAttackers call employees while posing as helpdesk staff.Require out-of-band verification for all IT support calls.
Remote access toolsVictims are told to install RMM or support software.Block unauthorized remote access tools with application control.
BYOD accessAttackers use personal devices to reach corporate VDI sessions.Limit VDI and VPN access to managed corporate devices.
Cloud storage exfiltrationStolen files are uploaded to Google Drive, OneDrive, or external servers.Monitor mass downloads and outbound transfers in real time.
Physical accessFake IT visitors try to copy data to removable drives.Log IDs, verify work orders, escort visitors, and restrict USB storage.

Extortion starts quickly after the files are stolen

UNC3753 does not usually encrypt systems like a classic ransomware crew. Instead, it steals data and then pressures the victim with threats of public exposure, regulatory fallout, and client notification.

Google said the group often sends an extortion email within 30 minutes of leaving the victimโ€™s environment. The emails typically give victims three days to respond and threaten to contact employees, clients, and the media if the organization refuses to negotiate.

The FBI also warned that SRG actors may call employees or clients of the victim organization to increase pressure. The FBI Cyber FLASH said the group uses the public-facing business-data-leaks[.]com site to post victim data.

Indicators linked to UNC3753 activity

Google listed several actor-controlled IP addresses, naming patterns, and infrastructure indicators tied to this campaign. Defenders should treat these indicators as hunting leads, not as standalone proof of compromise.

TypeIndicatorDescription
IPv4 address192.236.147.131UNC3753 actor-controlled IP address
IPv4 address192.236.147.138UNC3753 actor-controlled IP address
IPv4 address193.141.60.212UNC3753 actor-controlled IP address
IPv4 address192.236.154.158UNC3753 actor-controlled IP address
IPv4 address192.236.146.173UNC3753 actor-controlled IP address
IPv4 address174.169.162.62UNC3753 actor-controlled IP address
IPv4 address64.94.84.97UNC3753 actor-controlled IP address
Domain pattern<organization>-itdesk[.]comVishing and phishing infrastructure pattern
Domain pattern<organization>-it[.]comVishing and phishing infrastructure pattern
Domain pattern<organization>-helpdesk[.]comVishing and phishing infrastructure pattern
Data leak sitehxxps[:]//business-data-leaks[.]comVictim disclosure platform

Law firms need cyber and physical controls

Law firms are attractive targets because they hold concentrated stores of client data, merger details, legal strategies, regulatory files, financial records, and personal information. That data can create high pressure during an extortion attempt.

LEAKEDDATA DLS (Source – Google Cloud)

Defenders should not rely only on malware detection because UNC3753 often uses legitimate tools and victim-guided actions. The Google Cloud report recommends user awareness training, strict visitor verification, remote access controls, RMM restrictions, USB storage limits, network monitoring, and audit alerts for document platforms.

Security teams should also train staff to verify every IT call through a known internal channel. Employees should never install remote access software, join an unexpected screen-sharing session, or grant device access based only on an incoming call.

  • Require phishing-resistant MFA for document stores, email, VPN, VDI, and cloud platforms.
  • Block unauthorized RMM and remote support tools through application control.
  • Restrict Quick Assist, screen-control features, and meeting-based remote control where possible.
  • Alert on WinSCP or Rclone connections to external IP addresses.
  • Monitor large uploads to Google Drive, OneDrive, and other file-sharing services.
  • Disable USB storage installation and removable media writes on systems with sensitive data.
  • Verify all visiting technicians against pre-scheduled work orders and require escort at all times.
  • Use MITREโ€™s voice phishing technique and MITREโ€™s remote access software technique to map detections and staff training to known attacker behavior.

UNC3753 shows how modern extortion crews can bypass expensive security stacks by targeting trust, process gaps, and physical access. For law firms, the response needs to cover people, devices, cloud storage, remote access software, and the front desk at the same time.

FAQ

What is UNC3753?

UNC3753 is a financially motivated threat cluster also known as Luna Moth, Chatty Spider, and Silent Ransom Group. The group targets organizations with vishing, IT impersonation, legitimate remote access tools, data theft, and extortion.

Why is UNC3753 targeting law firms?

Law firms hold valuable client information, legal agreements, financial records, merger documents, regulatory files, and personal data. Attackers can use this information to pressure firms into paying during an extortion attempt.

How does UNC3753 gain access to victim systems?

UNC3753 usually impersonates IT staff through phone calls or phishing emails, then convinces employees to join screen-sharing sessions or install remote access tools. In some cases, actors also attempt physical office visits while posing as IT technicians.

Does UNC3753 use ransomware encryption?

The group usually focuses on data theft and extortion rather than encrypting systems. It steals sensitive files, then threatens to publish or sell the data if the victim does not respond.

How can law firms defend against UNC3753?

Law firms should verify IT calls out of band, restrict remote access tools, require phishing-resistant MFA, monitor mass file downloads, disable removable media where possible, and enforce strict visitor verification for all technical personnel.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages