Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors unc3753

Also known as: Luna Moth, Chatty Spider, tracked as, Silent Ransom Group, legal

Description

From January through May 2026, a financially motivated data theft extortion campaign executed by threat cluster UNC3753 targeted dozens of organizations across professional, legal, and financial services in the United States. The threat actors leverage voice phishing and social engineering techniques, posing as IT support to convince targets to host screen-sharing sessions and download remote monitoring and management utilities. Once inside environments, they conduct searches to locate and exfiltrate highly sensitive data including proprietary legal agreements, personally identifiable information, and financial records for subsequent extortion demands. The entire attack sequence often occurs within a single business day, with recent incidents showing data theft initiated in under an hour. Notably, threat actors have also accessed victims' systems in person, with individuals posing as IT technicians entering corporate offices to attempt direct exfiltration using USB storage media.

Goals & Targeting

Targeted Sectors

Financial services
Government
Legal services
Healthcare
Information technology
Utilities

Targeted Countries / Regions

United States of America
US

AI Analysis

· 1 week ago

Executive Summary

UNC3753 is a financially motivated nation-state threat actor targeting the financial-services and government sectors in the United States through voice phishing and social engineering. The group uses remote monitoring utilities to quickly exfiltrate sensitive data, employing both digital and physical methods for persistence.

Goals & Targeting

UNC3753 targets the financial-services and government sectors in the U.S., focusing on extracting high-value data for extortion. Their targeting likely reflects a strategic focus on sectors with rich sensitive information readily marketable. The actors' selection of the U.S. may stem from its economic influence and accessible infrastructure, offering higher financial rewards compared to other nations.

Enhanced Description

UNC3753 operates as a financially driven threat group primarily targeting the U.S. financial services and government sectors. Their tactics involve voice phishing and social engineering, where they pose as IT support to gain initial access. Once inside, they use remote monitoring utilities for data exfiltration within hours. Notably, they have attempted direct physical access using USB media, highlighting their multi-faceted approach. The group's goal is to steal sensitive data such as financial records and Personally Identifiable Information (PII) for extortion purposes. Their campaigns are characterized by rapid execution, often completing all stages within a single business day. Despite their sophisticated methods, specific details like toolkits and campaign history remain speculative.

Key Capabilities

  • Voice phishing
  • Social engineering campaigns
  • Remote monitoring utilities deployment
  • USB-based data exfiltration

MITRE ATT&CK Tactics

Cyber Espionage
Impacting Stability

ATT&CK Techniques

T1059
T1055
T1078.001
T1021
T1048.001
T1486

Software / Tooling

DarkComet
NJRAT
AnyConnect (example tools)

Campaigns & Victims

UNC3753's campaigns are short-lived, with incidents often resolved within a single business day. Their targeting of financial and government sectors suggests a focus on high-value data. The group's actors have attempted physical access via USB media, indicating adaptability. Though details about past operations remain hypothetical due to the 2026 timeframe, their methods suggest a professional and coordinated approach.

IOC Patterns

  • Voice phishing attempts posing as IT support
  • USB drops for direct data exfiltration
  • Suspicious remote monitoring tool installations
  • Rapid data exfiltration via network

Recommended Actions

  • Educate employees on spotting social engineering tactics
  • Monitor network traffic for signs of unauthorized access
  • Implement strict USB usage policies and physical security
  • Enhance credential management practices

Suggested Tags

APT
nation-state
financial-sector
government
espionage
extortion
data-theft

Confidence Assessment

High confidence in TTPs based on detailed description, but hypothetical operation timeframe (2026) requires further validation. Specific tools and historical campaigns remain unconfirmed.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. cloud.google.com — Cited by web research for: legal
  2. www.aha.org — Cited by web research for: CALENDAR
  3. www.crowdstrike.com — Cited by web research for: Phishing campaigns

Intel Summary

26

Techniques

41

Tools

0

Campaigns

20

IOCs

0

Observed Data

13

Tactics

Tags

APT
Phishing
Data Exfiltration
nation-state
financial-sector
government
espionage
extortion
data-theft

Details

Type
Nation-State
Primary Motivation
Financial gain
Confidence
55%
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.