Also known as: Luna Moth, Chatty Spider, tracked as, Silent Ransom Group, legal
From January through May 2026, a financially motivated data theft extortion campaign executed by threat cluster UNC3753 targeted dozens of organizations across professional, legal, and financial services in the United States. The threat actors leverage voice phishing and social engineering techniques, posing as IT support to convince targets to host screen-sharing sessions and download remote monitoring and management utilities. Once inside environments, they conduct searches to locate and exfiltrate highly sensitive data including proprietary legal agreements, personally identifiable information, and financial records for subsequent extortion demands. The entire attack sequence often occurs within a single business day, with recent incidents showing data theft initiated in under an hour. Notably, threat actors have also accessed victims' systems in person, with individuals posing as IT technicians entering corporate offices to attempt direct exfiltration using USB storage media.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC3753 is a financially motivated nation-state threat actor targeting the financial-services and government sectors in the United States through voice phishing and social engineering. The group uses remote monitoring utilities to quickly exfiltrate sensitive data, employing both digital and physical methods for persistence.
Goals & Targeting
UNC3753 targets the financial-services and government sectors in the U.S., focusing on extracting high-value data for extortion. Their targeting likely reflects a strategic focus on sectors with rich sensitive information readily marketable. The actors' selection of the U.S. may stem from its economic influence and accessible infrastructure, offering higher financial rewards compared to other nations.
Enhanced Description
UNC3753 operates as a financially driven threat group primarily targeting the U.S. financial services and government sectors. Their tactics involve voice phishing and social engineering, where they pose as IT support to gain initial access. Once inside, they use remote monitoring utilities for data exfiltration within hours. Notably, they have attempted direct physical access using USB media, highlighting their multi-faceted approach. The group's goal is to steal sensitive data such as financial records and Personally Identifiable Information (PII) for extortion purposes. Their campaigns are characterized by rapid execution, often completing all stages within a single business day. Despite their sophisticated methods, specific details like toolkits and campaign history remain speculative.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNC3753's campaigns are short-lived, with incidents often resolved within a single business day. Their targeting of financial and government sectors suggests a focus on high-value data. The group's actors have attempted physical access via USB media, indicating adaptability. Though details about past operations remain hypothetical due to the 2026 timeframe, their methods suggest a professional and coordinated approach.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in TTPs based on detailed description, but hypothetical operation timeframe (2026) requires further validation. Specific tools and historical campaigns remain unconfirmed.
No campaigns linked yet.
No observed data linked yet.
26
Techniques
41
Tools
0
Campaigns
20
IOCs
0
Observed Data
13
Tactics