Also known as: leakeddata, Luna Moth
a former Conti team Known victims: 108
Objectives
Executive Summary
SilentRansomGroup, also known as leakeddata, is a medium-sophisticated criminal threat actor primarily engaged in ransomware activities with a focus on organizational gain. The group has targeted numerous law firms and legal sector entities since first emerging in June 2022, leveraging their experience from previous associations like the Conti group.
Goals & Targeting
SilentRansomGroup's primary objective is financial gain through ransomware campaigns. Their targeting strategy focuses on sectors where sensitive client data is abundant and easily monetizable, such as law firms. The group has demonstrated a preference for attacking legal sector entities, possibly due to the high-value nature of their data and the potential for successful extortion attempts.
Enhanced Description
SilentRansomGroup is a cybercriminal threat actor that operates with moderate sophistication, focusing primarily on ransomware attacks. The group has demonstrated persistence over its operational timeline, first appearing in mid-2022 and continuing to be observed as of June 2026. SilentRansomGroup has targeted numerous law firms and legal sector entities, suggesting a focus on high-value industries with deep client data repositories. Known for their association with the Conti group, SilentRansomGroup inherits some of the same attack patterns but operates independently as a distinct entity today.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
SilentRansomGroup has conducted multiple campaigns targeting law firms and legal entities. Their operational tempo indicates a steady but not overly aggressive campaign pattern, suggesting they focus on successful extortion rather than rapidattacks. The group has targeted victims in North America and Europe, with the majority of their activity observed in the U.S. Their campaigns often involve double extortion tactics, where both data theft and encryption are employed to maximize ransom payments.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the group's identity and targeting patterns, but limited visibility into specific tools or techniques beyond those inferred from past associations like Conti. No direct evidence of their TTPs is publicly available.
No techniques linked yet.
No tools linked yet.
SilentRansomGroup: He..t S..it.
Ransomware attack attributed to SilentRansomGroup. | Sector: Not Found | [AI generated] N/A | Source: https://www.ransomware.live/id/SGUuLnQgUy4uaXQuQFNpbGVudFJhbnNvbUdyb3Vw
Jun 17, 2026
TLP:CLEARNo observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
30
Campaigns
0
IOCs
0
Observed Data
0
Tactics