Also known as: CHATTY SPIDER, Luna Moth, UNC3753, Silent Ransom Group, UAT4356 by Talos, legal, tracked as, easterly waves, Project Spy, Cridex, similar to Sliver, Cobalt Strike, consists of multiple components, NoFive, Plat1, U2DiskWatch, control module, Storm-1175
Storm-0252 is an advanced threat actor that operates as a cluster of sub‑groups, each identified with aliases such as CHATTY SPIDER, Silent Ransom Group and Luna Moth. The group first appears in the public domain around March 2022 and has since targeted legal, financial, government and critical infrastructure organisations in more than thirty countries. Their primary motive is monetary gain; they obtain data of a confidential nature through social engineering and remote execution, then extort victims by threatening to publish or sell the information. Operationally, Storm‑0252 leverages vishing techniques that present actors as internal IT support staff or subscription‑billing clerks. Victims are persuaded to install legitimate Remote Monitoring and Management (RMM) tools such as Cobalt Strike‑derived clients, PowerShell backdoors or other custom RATs. The attackers then perform system discovery, credential dumping, process injection, file‑system exfiltration, and employ encrypted channels to the cloud or USB devices before releasing demand letters. In addition to remote access, the group embeds persistence mechanisms including scheduled tasks (T1053.005), registry run keys (T1547.001) and boot scripting. The intelligence community has documented several malware families related to this actor: TrickBot, Mimikatz, the Rclone cloud‑exfil tool, Cobalt Strike modules, and a range of ransomware such as Medusa and Conti used in early campaigns. While direct evidence sometimes points to legacy backdoors like T9000 and Plat1, the group continues to adapt by deploying newer custom payloads that obfuscate themselves from traditional AV signatures.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Storm-0252, also known as CHATTY SPIDER or UNC3753, is a Russia‑based eCrime cluster that specialises in financially motivated data theft and extortion campaigns. Using voice phishing (vishing) to convince victims into remote monitoring sessions, the group exfiltrates highly valuable information from large organisations across many sectors and regions before threatening publication of the stolen data. The organization’s tactics have evolved from ransomware delivery to a pure steal‑and‑blackmail model over the past three years.
Goals & Targeting
The actor’s strategic objective is straightforward financial gain; they seek high‑value targets whose data can command large ransom or blackmail fees. By focusing on sectors with sensitive legal agreements, personally identifiable information (PII), and regulatory compliance burdens—such as law firms, finance, government, energy, and healthcare—they maximise the threat of a public leak. Victims are generally mid‑ to large‑scale enterprises that rely heavily on RMM tools, thereby lowering the technical barrier for remote intrusion. Their geographic preference spans much of the globe but shows particular activity in the U.S., Russia, Ukraine, Brazil and Western Europe, indicating a deliberate aim to raid jurisdictions with robust financial infrastructures and high public‑profile organizations.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Storm‑0252’s campaigns follow a cyclical pattern: initial engagement via vishing to install low‑visibility RMM tools, rapid lateral movement and credential harvesting, followed by data exfiltration through cloud or USB. The attack cadence has increased from sporadic incidents in early 2023 to near-monthly operations in 2025, reflecting operational maturity and a widening victim pool. Historically the group employed ransomware modules (LOCKBIT.BLACK) but has pivoted toward pure data theft-extort tactics, underscoring a shift to higher profit margins with lower deployment risk. The actor frequently uses well‑known phishing PDFs or subscription‑renewal alerts that route victims to controlled call centers, thereby creating an internal IT pretext. Their infrastructure overlaps across fast‑flux domains and bulletproof hosting services, making attribution complex but evidence still links them to Russian origin through domain registrations and the use of Russian‑centric RMM platforms.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in the actor’s vishing-based RMM delivery, financial motivation and sector targeting is high, as corroborated by multiple vendor reports and documented campaign patterns. Confidence in specific malware associations (e.g., Cobalt Strike, Mimikatz) is moderate, derived from linked tool lists but lacking direct attribution evidence. The absence of detailed timeline or country‑level deployment frequency limits precise assessment of operational tempo, though the observed shift toward pure data exfiltration suggests a strategic evolution that remains under-evaluated. Unknowns include true geographic focus beyond broad lists and whether newer backdoors such as T9000 are actively deployed in recent incidents.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
56
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics