UNC3753 Targets US Law Firms With Vishing, RMM Tools, and Physical Intrusions
UNC3753 is targeting U.S. law firms and other professional services organizations in a fast-moving data theft and extortion campaign that relies on phone calls, remote access tools, and in some cases in-person office visits.
The financially motivated group, also known as Luna Moth, Chatty Spider, and Silent Ransom Group, has been active since at least 2022. In its latest wave, the group targeted organizations across legal, professional, and financial services between January and May 2026, according to a Google Cloud threat intelligence report.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
The campaign stands out because it avoids traditional malware in many cases. Instead, attackers call employees while pretending to be internal IT staff, convince them to join screen-sharing sessions, and push them into installing legitimate remote monitoring and management tools.
UNC3753 moves from phone call to data theft within hours
Googleโs Mandiant and Google Threat Intelligence Group said some UNC3753 intrusions moved from first contact to data theft and extortion within a single business day. In recent cases, file searching, staging, and exfiltration began in under an hour.
The group usually starts with a simple invoice-themed email from a consumer email account. These messages often contain no malicious links or attachments. Their goal is to create concern, so the target becomes more likely to answer a follow-up call from someone claiming to work for IT support.
This tactic maps closely to vishing, where attackers use voice calls to manipulate victims. MITRE ATT&CK describes spearphishing voice as the use of phone calls to obtain sensitive information, often while posing as a trusted source such as technical support.
| Stage | What UNC3753 does | Why it works |
|---|---|---|
| Pretext email | Sends a harmless-looking invoice or IT-themed message. | The email avoids malicious links and attachments. |
| Vishing call | Calls the employee while posing as IT or security staff. | The attacker builds trust through direct conversation. |
| Screen-sharing session | Guides the victim into joining a remote support session. | The victim performs actions that security tools may not block. |
| RMM installation | Pushes AnyDesk, Bomgar, Zoho Assist, or SuperOps RMM. | These tools can look legitimate in business environments. |
| Data theft | Searches, stages, and exfiltrates sensitive files. | The group focuses on documents valuable for extortion. |
Attackers abuse legitimate remote support software
Once the target joins a session, UNC3753 uses screen-sharing tools and remote access utilities to bypass normal perimeter security. Google observed the group using Zoom, Microsoft Teams, Microsoft Terminal Services, Quick Assist, AnyDesk, Bomgar, Zoho Assist, and a SuperOps RMM agent in different incidents.
The group also uses Privnote to send installation links or commands. Since Privnote messages disappear after they are opened, this can reduce evidence left in chat logs, browser history, or copied messages.
Remote monitoring and management software has legitimate business uses, but attackers can abuse it for interactive access. MITRE ATT&CK lists remote access software as a technique where adversaries use legitimate support tools to control target systems or maintain access.
BYOD devices and virtual desktops expand the attack path
Some UNC3753 intrusions began on personal laptops used for work. After gaining control of a Bring Your Own Device endpoint, attackers accessed corporate virtual desktop environments through Windows 365 or Citrix clients.
From there, they searched corporate file stores, mapped network drives, OneDrive folders, and legal document management systems. Google said the group searched iManage repositories for files containing tax records, W-2, W-9 and 1099 forms, corporate agreements, audit records, and Social Security numbers.
The attackers then staged files in folders the victim could access, often inside Downloads or profile paths. In several cases, they exfiltrated files by using portable WinSCP, Rclone, cloud storage uploads, or direct uploads from the victimโs browser.
- Common tools observed include AnyDesk, Bomgar, Zoho Assist, SuperOps RMM, WinSCP, and Rclone.
- Common lures include invoice messages, IT support calls, security checks, and data migration claims.
- Common targets include legal agreements, tax documents, client files, financial records, and personal information.
- Common access paths include screen-sharing sessions, BYOD laptops, VDI environments, and cloud storage accounts.
The group also uses physical office intrusions
The FBI warned in a May 2026 Cyber FLASH alert that Silent Ransom Group is targeting law firms through IT-themed social engineering calls and phishing emails. The FBI advisory said actors may send someone in person to a victimโs office if remote social engineering fails.
In those incidents, the person claims to be IT support and says they need to image a device or create a backup. Once they get access to the computer, they try to copy data to a USB drive or external hard drive.

Google said it assessed these physical intrusion attempts as likely linked to UNC3753 based on structural, timeline, and targeting overlaps. The shift is important because it moves the threat beyond email security and endpoint monitoring into front-desk procedures, visitor controls, and removable media policies.
| Risk area | Observed behavior | Recommended control |
|---|---|---|
| IT impersonation | Attackers call employees while posing as helpdesk staff. | Require out-of-band verification for all IT support calls. |
| Remote access tools | Victims are told to install RMM or support software. | Block unauthorized remote access tools with application control. |
| BYOD access | Attackers use personal devices to reach corporate VDI sessions. | Limit VDI and VPN access to managed corporate devices. |
| Cloud storage exfiltration | Stolen files are uploaded to Google Drive, OneDrive, or external servers. | Monitor mass downloads and outbound transfers in real time. |
| Physical access | Fake IT visitors try to copy data to removable drives. | Log IDs, verify work orders, escort visitors, and restrict USB storage. |
Extortion starts quickly after the files are stolen
UNC3753 does not usually encrypt systems like a classic ransomware crew. Instead, it steals data and then pressures the victim with threats of public exposure, regulatory fallout, and client notification.
Google said the group often sends an extortion email within 30 minutes of leaving the victimโs environment. The emails typically give victims three days to respond and threaten to contact employees, clients, and the media if the organization refuses to negotiate.
The FBI also warned that SRG actors may call employees or clients of the victim organization to increase pressure. The FBI Cyber FLASH said the group uses the public-facing business-data-leaks[.]com site to post victim data.
Indicators linked to UNC3753 activity
Google listed several actor-controlled IP addresses, naming patterns, and infrastructure indicators tied to this campaign. Defenders should treat these indicators as hunting leads, not as standalone proof of compromise.
| Type | Indicator | Description |
|---|---|---|
| IPv4 address | 192.236.147.131 | UNC3753 actor-controlled IP address |
| IPv4 address | 192.236.147.138 | UNC3753 actor-controlled IP address |
| IPv4 address | 193.141.60.212 | UNC3753 actor-controlled IP address |
| IPv4 address | 192.236.154.158 | UNC3753 actor-controlled IP address |
| IPv4 address | 192.236.146.173 | UNC3753 actor-controlled IP address |
| IPv4 address | 174.169.162.62 | UNC3753 actor-controlled IP address |
| IPv4 address | 64.94.84.97 | UNC3753 actor-controlled IP address |
| Domain pattern | <organization>-itdesk[.]com | Vishing and phishing infrastructure pattern |
| Domain pattern | <organization>-it[.]com | Vishing and phishing infrastructure pattern |
| Domain pattern | <organization>-helpdesk[.]com | Vishing and phishing infrastructure pattern |
| Data leak site | hxxps[:]//business-data-leaks[.]com | Victim disclosure platform |
Law firms need cyber and physical controls
Law firms are attractive targets because they hold concentrated stores of client data, merger details, legal strategies, regulatory files, financial records, and personal information. That data can create high pressure during an extortion attempt.

Defenders should not rely only on malware detection because UNC3753 often uses legitimate tools and victim-guided actions. The Google Cloud report recommends user awareness training, strict visitor verification, remote access controls, RMM restrictions, USB storage limits, network monitoring, and audit alerts for document platforms.
Security teams should also train staff to verify every IT call through a known internal channel. Employees should never install remote access software, join an unexpected screen-sharing session, or grant device access based only on an incoming call.
- Require phishing-resistant MFA for document stores, email, VPN, VDI, and cloud platforms.
- Block unauthorized RMM and remote support tools through application control.
- Restrict Quick Assist, screen-control features, and meeting-based remote control where possible.
- Alert on WinSCP or Rclone connections to external IP addresses.
- Monitor large uploads to Google Drive, OneDrive, and other file-sharing services.
- Disable USB storage installation and removable media writes on systems with sensitive data.
- Verify all visiting technicians against pre-scheduled work orders and require escort at all times.
- Use MITREโs voice phishing technique and MITREโs remote access software technique to map detections and staff training to known attacker behavior.
UNC3753 shows how modern extortion crews can bypass expensive security stacks by targeting trust, process gaps, and physical access. For law firms, the response needs to cover people, devices, cloud storage, remote access software, and the front desk at the same time.
FAQ
UNC3753 is a financially motivated threat cluster also known as Luna Moth, Chatty Spider, and Silent Ransom Group. The group targets organizations with vishing, IT impersonation, legitimate remote access tools, data theft, and extortion.
Law firms hold valuable client information, legal agreements, financial records, merger documents, regulatory files, and personal data. Attackers can use this information to pressure firms into paying during an extortion attempt.
UNC3753 usually impersonates IT staff through phone calls or phishing emails, then convinces employees to join screen-sharing sessions or install remote access tools. In some cases, actors also attempt physical office visits while posing as IT technicians.
The group usually focuses on data theft and extortion rather than encrypting systems. It steals sensitive files, then threatens to publish or sell the data if the victim does not respond.
Law firms should verify IT calls out of band, restrict remote access tools, require phishing-resistant MFA, monitor mass file downloads, disable removable media where possible, and enforce strict visitor verification for all technical personnel.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages