Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Luna Moth

Also known as: Silent Ransom, TG2729, Chatty Spider, UNC3753, is, is targeting law firms, Silent Ransom Group, legal, tracked as, the American Moon Moth, insurance, Storm-0252

Description

Luna Moth—also referenced as Silent Ransom Group, TG2729, Chatty Spider, UNC3753, or the American Moon Moth—is a financially motivated threat actor with a pronounced focus on law‑and‑financial sectors across the United States. The group employs high‑frequency callback phishing, vishing (voice phishing), and spearphishing campaigns to deceive victims into installing Remote Monitoring and Management (RMM) utilities such as Quick Assist or AnyDesk. By leveraging these legitimate tools, attackers achieve remote host-level access with minimal lateral movement, enabling immediate exfiltration of proprietary legal agreements, personal identification data, and financial records. Once foothold, Luna Moth exerts ransom leverage by demanding $1‑$8 million and threatening to publish the compromised data. The operation demonstrates a strategic pivot from ransomware encryptions toward a hybrid model that combines data theft with extortion, thereby reducing reliance on encryption while magnifying potential profit. Their use of external services (e.g., cloud storage for exfiltration) and stealthy execution via legitimate binaries indicates a sophisticated understanding of defensive perimeter techniques. The actor’s operational tempo is rapid; each campaign comprises numerous callback phishing attempts over short periods, suggesting an automated or semi‑automated infrastructure. Its persistence in targeting professional service firms illustrates that Luna Moth prioritizes high‑value targets that can afford substantial ransom payments and are likely to suffer reputational damage if data leaks. Tactics include initial social engineering (spearfishing, vishing) leading to execution via user action or remote tool installation; credential dumping and privilege escalation through well‑known tools such as Mimikatz and LaZagne; persistence via registry run keys and BITS jobs; and exfiltration via cloud services or SMB shares. The actor also modifies system registries and clears command history, evidencing robust defense evasion measures. Overall, Luna Moth represents a serious threat to the legal and financial infrastructure in the U.S., leveraging socially engineered remote access and data‑breach extortion to maximize financial gain.

Goals & Targeting

Targeted Sectors

Legal services
Financial services
Information technology
Healthcare
Utilities
Government
Defense
Energy
Education
Manufacturing
Critical infrastructure

Targeted Countries / Regions

US
CN
GB
UA

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 days ago

Executive Summary

Luna Moth, operating under the moniker Silent Ransom Group among others, carries out high‑tempo callback phishing campaigns against law and financial firms in the United States. The group uses social engineering to coerce victims into installing remote management tools or sharing screen‑sharing sessions, which then allows direct access, data exfiltration, and extortion demands ranging from $1 million to $8 million. Unlike traditional ransomware operators, Luna Moth focuses on a data‑breach‑extortion model, exploiting trusted legitimate utilities (RMM software) for persistence and cover while threatening public leak of the stolen material if ransom is not paid.

Goals & Targeting

Luna Moth’s strategic objective is to secure large ransoms by marrying data theft with public‑leak pressure. The actor specifically targets high‑profile law firms, financial services, and corporate entities that handle sensitive client data—organizations where a breach would cause significant reputational harm. By exploiting legitimate remote tools for entry and persistence, Luna Moth minimizes detection risk while broadening its reach across industries such as energy, healthcare, utilities, defense, education, and manufacturing. The ultimate aim is to dominate the victim’s network quickly, exfiltrate high‑value data, and demand a substantial payout before any law‑enforced retaliation can be mounted. Key capabilities include sophisticated callback-vishing workflows, precise user‑execution manipulation, and dynamic remote management deployments that obfuscate malicious activity. The group also appears to have the operational capacity for rapid campaign expansion, suggesting an underlying infrastructure capable of supporting multiple simultaneous phishing vectors. This focus on financially lucrative sectors aligns with broader trends of ransomware‑like extortion where actors prefer high-impact targets over mass compromise.

Enhanced Description

Key Capabilities

  • spearfishing attachments
  • spearfishing links
  • callback phishing
  • false subscription scams
  • remote management tool installation via legitimate binaries
  • user execution via phone call or link
  • physical intrusion at target sites
  • voice phishing (vishing)
  • spearphishing voice
  • social engineering deception
  • remote access through RMM tools
  • screen‑sharing sessions granting host privileges
  • malicious executable downloads
  • exfiltration of proprietary legal agreements and financial records
  • exfiltration of PII
  • manipulation into executing attacker tasks

MITRE ATT&CK Tactics

Initial Access
Execution
Exfiltration

ATT&CK Techniques

T1560.001
T1218.011
T1222.002
T1133
T1204.002
T1087.001
T1566.002
T1021.004
T1083
T1070.003
T1219
T1112
T1555.003
T1136.001
T1003.001
T1072
T1059.001
T1547.001
T1098
T1068
T1027
T1486
T1566.004
T1567.002
T1197
T1003.008
T1059.003
T1070.004
T1046
T1550.002
T1105
T1021.001
T1562.004
T1070.001
T1204
T1566
T1566.001
T1566.003
T1606.002

Software / Tooling

Lumma Stealer
Royal Ransomware
Black Basta ransomware
Hikit
Ryuk ransomware
REvil ransomware
AppleJeus
INC Ransomware
Rclone
Mimikatz
LaZagne
Quick Assist
Netscan
PowerShell
Dark
AnyDesk
Nexus
Conti ransomware
Luna
Curator
Global
Handala
Kimsuky
ROMCOM RAT
Splinter
Stealc
Void
WildFire

Campaigns & Victims

Since at least March 2022, Luna Moth has conducted a series of callback‑phishing operations against a broad spectrum of professional firms. Campaigns are characterized by rapid deployment of tailored spearphishing and vishing emails that prompt victims to install RMM utilities or share screen sessions. Once access is achieved, the actor exfiltrates sensitive data—primarily legal agreements, PII, and financial records—and threatens publication unless a sizable ransom is paid. Operations display a pattern of minimal lateral movement, high-value target selection, and exploitation of legitimate remote tools to reduce footprint. The group’s infrastructure includes use of public cloud storage for exfiltration and the deployment of multiple ransomware families in later stages of some operations. Victim types span law firms, financial service providers, energy utilities, healthcare systems, and government agencies, illustrating Luna Moth’s adaptability across vertically regulated sectors. Although not all campaigns have been publicly disclosed, available reports suggest a consistent operational tempo with each active attack lasting weeks to months before pivoting to new targets or launching a fresh wave of phishing attempts.

IOC Patterns

  • phishing emails with PDF attachments containing phone numbers for callback requests
  • malicious URLs used during vishing conversations
  • downloaded executable for remote management tools (e.g., Quick Assist, AnyDesk)
  • IP addresses used as command-and-control endpoints
  • domains hosting malicious payloads
  • files containing malicious binaries such as rundll32.exe or netscan.exe
  • emails spoofing legitimate support contacts from popular vendors

Recommended Actions

  • Deploy and enforce SPF, DKIM, and DMARC email authentication to reduce spoofed messages.
  • Conduct comprehensive user training focused on spearphishing, vishing, false‑subscription scams, and the dangers of clicking unknown links or calling unfamiliar numbers.
  • Implement detection for suspicious attachment downloads and correlate mail logs with process creation events to identify malicious activity early. Enforce MFA across all systems and validate authentication prompts to mitigate credential harvesting. Monitor outbound network traffic for anomalous connections following receipt of suspicious attachments or link clicks. Restrict the use of RMM tools such as Quick Assist, AnyDesk, and other legitimate remote‑access utilities; whitelist approved deployments and audit usage logs regularly. Block known malicious URLs, domains, IP addresses, and file hashes using network security controls and threat‑intelligence feeds.

ATT&CK Techniques

Collection
1 technique
Privilege Escalation
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 8 IPv4 Address 6 SHA-256 Hash 3 Filename 3

References

  1. attack.mitre.org — Cited by web research for: T1566.001
  2. unit42.paloaltonetworks.com — Cited by web research for: T1133
  3. cloud.google.com — Cited by web research for: T1204.002
  4. attack.mitre.org — Cited by web research for: Quick Assist

Intel Summary

42

Techniques

51

Tools

0

Campaigns

39

IOCs

0

Observed Data

14

Tactics

Tags

Ransomware
Critical Infrastructure
Phishing
Data Exfiltration
APT
Extortion
Financial-Sector
Legal-Sector
Social-Engineering

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.