Also known as: Silent Ransom, TG2729, Chatty Spider, UNC3753, is, is targeting law firms, Silent Ransom Group, legal, tracked as, the American Moon Moth, insurance, Storm-0252
Luna Moth—also referenced as Silent Ransom Group, TG2729, Chatty Spider, UNC3753, or the American Moon Moth—is a financially motivated threat actor with a pronounced focus on law‑and‑financial sectors across the United States. The group employs high‑frequency callback phishing, vishing (voice phishing), and spearphishing campaigns to deceive victims into installing Remote Monitoring and Management (RMM) utilities such as Quick Assist or AnyDesk. By leveraging these legitimate tools, attackers achieve remote host-level access with minimal lateral movement, enabling immediate exfiltration of proprietary legal agreements, personal identification data, and financial records. Once foothold, Luna Moth exerts ransom leverage by demanding $1‑$8 million and threatening to publish the compromised data. The operation demonstrates a strategic pivot from ransomware encryptions toward a hybrid model that combines data theft with extortion, thereby reducing reliance on encryption while magnifying potential profit. Their use of external services (e.g., cloud storage for exfiltration) and stealthy execution via legitimate binaries indicates a sophisticated understanding of defensive perimeter techniques. The actor’s operational tempo is rapid; each campaign comprises numerous callback phishing attempts over short periods, suggesting an automated or semi‑automated infrastructure. Its persistence in targeting professional service firms illustrates that Luna Moth prioritizes high‑value targets that can afford substantial ransom payments and are likely to suffer reputational damage if data leaks. Tactics include initial social engineering (spearfishing, vishing) leading to execution via user action or remote tool installation; credential dumping and privilege escalation through well‑known tools such as Mimikatz and LaZagne; persistence via registry run keys and BITS jobs; and exfiltration via cloud services or SMB shares. The actor also modifies system registries and clears command history, evidencing robust defense evasion measures. Overall, Luna Moth represents a serious threat to the legal and financial infrastructure in the U.S., leveraging socially engineered remote access and data‑breach extortion to maximize financial gain.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Luna Moth, operating under the moniker Silent Ransom Group among others, carries out high‑tempo callback phishing campaigns against law and financial firms in the United States. The group uses social engineering to coerce victims into installing remote management tools or sharing screen‑sharing sessions, which then allows direct access, data exfiltration, and extortion demands ranging from $1 million to $8 million. Unlike traditional ransomware operators, Luna Moth focuses on a data‑breach‑extortion model, exploiting trusted legitimate utilities (RMM software) for persistence and cover while threatening public leak of the stolen material if ransom is not paid.
Goals & Targeting
Luna Moth’s strategic objective is to secure large ransoms by marrying data theft with public‑leak pressure. The actor specifically targets high‑profile law firms, financial services, and corporate entities that handle sensitive client data—organizations where a breach would cause significant reputational harm. By exploiting legitimate remote tools for entry and persistence, Luna Moth minimizes detection risk while broadening its reach across industries such as energy, healthcare, utilities, defense, education, and manufacturing. The ultimate aim is to dominate the victim’s network quickly, exfiltrate high‑value data, and demand a substantial payout before any law‑enforced retaliation can be mounted. Key capabilities include sophisticated callback-vishing workflows, precise user‑execution manipulation, and dynamic remote management deployments that obfuscate malicious activity. The group also appears to have the operational capacity for rapid campaign expansion, suggesting an underlying infrastructure capable of supporting multiple simultaneous phishing vectors. This focus on financially lucrative sectors aligns with broader trends of ransomware‑like extortion where actors prefer high-impact targets over mass compromise.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since at least March 2022, Luna Moth has conducted a series of callback‑phishing operations against a broad spectrum of professional firms. Campaigns are characterized by rapid deployment of tailored spearphishing and vishing emails that prompt victims to install RMM utilities or share screen sessions. Once access is achieved, the actor exfiltrates sensitive data—primarily legal agreements, PII, and financial records—and threatens publication unless a sizable ransom is paid. Operations display a pattern of minimal lateral movement, high-value target selection, and exploitation of legitimate remote tools to reduce footprint. The group’s infrastructure includes use of public cloud storage for exfiltration and the deployment of multiple ransomware families in later stages of some operations. Victim types span law firms, financial service providers, energy utilities, healthcare systems, and government agencies, illustrating Luna Moth’s adaptability across vertically regulated sectors. Although not all campaigns have been publicly disclosed, available reports suggest a consistent operational tempo with each active attack lasting weeks to months before pivoting to new targets or launching a fresh wave of phishing attempts.
IOC Patterns
Recommended Actions
No campaigns linked yet.
No observed data linked yet.
42
Techniques
51
Tools
0
Campaigns
39
IOCs
0
Observed Data
14
Tactics