Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-0252

Also known as: CHATTY SPIDER, Luna Moth, UNC3753, Silent Ransom Group, UAT4356 by Talos, legal, tracked as, easterly waves, Project Spy, Cridex, similar to Sliver, Cobalt Strike, consists of multiple components, NoFive, Plat1, U2DiskWatch, control module, Storm-1175

Description

Storm-0252 is an advanced threat actor that operates as a cluster of sub‑groups, each identified with aliases such as CHATTY SPIDER, Silent Ransom Group and Luna Moth. The group first appears in the public domain around March 2022 and has since targeted legal, financial, government and critical infrastructure organisations in more than thirty countries. Their primary motive is monetary gain; they obtain data of a confidential nature through social engineering and remote execution, then extort victims by threatening to publish or sell the information. Operationally, Storm‑0252 leverages vishing techniques that present actors as internal IT support staff or subscription‑billing clerks. Victims are persuaded to install legitimate Remote Monitoring and Management (RMM) tools such as Cobalt Strike‑derived clients, PowerShell backdoors or other custom RATs. The attackers then perform system discovery, credential dumping, process injection, file‑system exfiltration, and employ encrypted channels to the cloud or USB devices before releasing demand letters. In addition to remote access, the group embeds persistence mechanisms including scheduled tasks (T1053.005), registry run keys (T1547.001) and boot scripting. The intelligence community has documented several malware families related to this actor: TrickBot, Mimikatz, the Rclone cloud‑exfil tool, Cobalt Strike modules, and a range of ransomware such as Medusa and Conti used in early campaigns. While direct evidence sometimes points to legacy backdoors like T9000 and Plat1, the group continues to adapt by deploying newer custom payloads that obfuscate themselves from traditional AV signatures.

Goals & Targeting

Targeted Sectors

Financial services
Government
Manufacturing
Defense
Telecommunications
Transportation
Energy
Legal services
Healthcare
Critical infrastructure
Education
Construction
Utilities
Media
Information technology
Retail
Aerospace
Chemical
Mining
Nuclear
Pharmaceutical
Aviation
Maritime
Hospitality
Gaming
Food agriculture

Targeted Countries / Regions

US
CN
RU
UA
BR
KR
GB
IN
AU
IR
PL
IL
MX
DE
ES
CA
JP
RO
TR
SY
TW
IT
SA
FR
VN
SG
PK
AE
NL
AZ
KZ

AI Analysis

Grounded in web research
· 5 hours ago

Executive Summary

Storm-0252, also known as CHATTY SPIDER or UNC3753, is a Russia‑based eCrime cluster that specialises in financially motivated data theft and extortion campaigns. Using voice phishing (vishing) to convince victims into remote monitoring sessions, the group exfiltrates highly valuable information from large organisations across many sectors and regions before threatening publication of the stolen data. The organization’s tactics have evolved from ransomware delivery to a pure steal‑and‑blackmail model over the past three years.

Goals & Targeting

The actor’s strategic objective is straightforward financial gain; they seek high‑value targets whose data can command large ransom or blackmail fees. By focusing on sectors with sensitive legal agreements, personally identifiable information (PII), and regulatory compliance burdens—such as law firms, finance, government, energy, and healthcare—they maximise the threat of a public leak. Victims are generally mid‑ to large‑scale enterprises that rely heavily on RMM tools, thereby lowering the technical barrier for remote intrusion. Their geographic preference spans much of the globe but shows particular activity in the U.S., Russia, Ukraine, Brazil and Western Europe, indicating a deliberate aim to raid jurisdictions with robust financial infrastructures and high public‑profile organizations.

Enhanced Description

Key Capabilities

  • Sophisticated vishing social engineering
  • Remote monitoring via legitimate RMM tools
  • PowerShell and Windows command‑shell execution
  • Persistence through scheduled tasks and registry run keys
  • Process injection and DLL side loading
  • Credential dumping (LSASS memory, SAM files)
  • Data discovery across file systems and network shares
  • Automated exfiltration to cloud services and USB devices
  • Encrypted data transport for impact or stealth
  • Use of custom RATs and modular backdoors
  • Dynamic shift between ransomware delivery and pure data theft
  • Adaptability to target different industries globally

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Exfiltration
Impact

ATT&CK Techniques

T1204.002
T1053.005
T1037
T1033
T1133
T1003.002
T1036.005
T1082
T1005
T1140
T1219
T1055
T1572
T1003.001
T1016
T1020
T1083
T1057
T1059.001
T1547.001
T1052.001
T1486
T1566.004
T1685
T1567.002
T1059.003
T1046
T1105
T1653
T1021.001
T1569.002
T1562

Software / Tooling

TrickBot
Mimikatz
Cobalt Strike
PowerShell backdoor scripts
Rclone
Medusa ransomware
Conti ransomware
REvil
SodaMaster
PlugX
Pikabot
Gootkit
PUBLOAD
NoFive (T9000)
Plat1

Campaigns & Victims

Storm‑0252’s campaigns follow a cyclical pattern: initial engagement via vishing to install low‑visibility RMM tools, rapid lateral movement and credential harvesting, followed by data exfiltration through cloud or USB. The attack cadence has increased from sporadic incidents in early 2023 to near-monthly operations in 2025, reflecting operational maturity and a widening victim pool. Historically the group employed ransomware modules (LOCKBIT.BLACK) but has pivoted toward pure data theft-extort tactics, underscoring a shift to higher profit margins with lower deployment risk. The actor frequently uses well‑known phishing PDFs or subscription‑renewal alerts that route victims to controlled call centers, thereby creating an internal IT pretext. Their infrastructure overlaps across fast‑flux domains and bulletproof hosting services, making attribution complex but evidence still links them to Russian origin through domain registrations and the use of Russian‑centric RMM platforms.

IOC Patterns

  • Spearphishing via vishing with PDF attachments
  • Remote monitoring tool installation (RMM) after phone call
  • Exfiltration over cloud storage such as AWS S3 or Google Drive
  • Use of legitimate PowerShell scripts for persistence
  • Stealthy use of USB device exfiltration paths
  • Dynamic domain registration and fast‑flux C2 infrastructure
  • Encrypted command-and-control traffic via TLS

Recommended Actions

  • Strengthen endpoint security with EDR that detects unusual RMM tool installations or lateral movement
  • Deploy call‑center authentication (MFA, caller ID verification) to validate internal support requests
  • Enforce least privilege for remote tooling and enforce strict change management
  • Monitor for anomalous scheduled tasks and registry run key modifications
  • Block traffic to known bad domains and implement DNS security filtering
  • Enable logging of LSASS memory dumps and other credential‑dumping indicators
  • Educate staff on vishing techniques and conduct regular phishing simulation training
  • Segment network to limit lateral movement of remotely installed RATs

Suggested Tags

eCrime
Financial extortion
Data theft
Vishing
RMM exploitation
Global campaign
High-value sectors (law, finance, government)
Remote access tool usage
Ransomware-related
Targeted phishing
Industrial espionage
Cloud exfiltration

Confidence Assessment

The confidence in the actor’s vishing-based RMM delivery, financial motivation and sector targeting is high, as corroborated by multiple vendor reports and documented campaign patterns. Confidence in specific malware associations (e.g., Cobalt Strike, Mimikatz) is moderate, derived from linked tool lists but lacking direct attribution evidence. The absence of detailed timeline or country‑level deployment frequency limits precise assessment of operational tempo, though the observed shift toward pure data exfiltration suggests a strategic evolution that remains under-evaluated. Unknowns include true geographic focus beyond broad lists and whether newer backdoors such as T9000 are actively deployed in recent incidents.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: Project Spy
  2. cloud.google.com — Cited by web research for: T1566.004
  3. blog.talosintelligence.com — Cited by web research for: T1037
  4. www.dragos.com — Cited by web research for: Gentlemen

Intel Summary

40

Techniques

56

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

APT
espionage
emerging_threat
eCrime
Financial extortion
Data theft
Vishing
RMM exploitation
Global campaign
High-value sectors (law, finance, government)
Remote access tool usage
Ransomware-related
Targeted phishing
Industrial espionage
Cloud exfiltration

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.