Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors silentransomgroup

Also known as: leakeddata, Luna Moth

Description

a former Conti team Known victims: 108

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

SilentRansomGroup, also known as leakeddata, is a medium-sophisticated criminal threat actor primarily engaged in ransomware activities with a focus on organizational gain. The group has targeted numerous law firms and legal sector entities since first emerging in June 2022, leveraging their experience from previous associations like the Conti group.

Goals & Targeting

SilentRansomGroup's primary objective is financial gain through ransomware campaigns. Their targeting strategy focuses on sectors where sensitive client data is abundant and easily monetizable, such as law firms. The group has demonstrated a preference for attacking legal sector entities, possibly due to the high-value nature of their data and the potential for successful extortion attempts.

Enhanced Description

SilentRansomGroup is a cybercriminal threat actor that operates with moderate sophistication, focusing primarily on ransomware attacks. The group has demonstrated persistence over its operational timeline, first appearing in mid-2022 and continuing to be observed as of June 2026. SilentRansomGroup has targeted numerous law firms and legal sector entities, suggesting a focus on high-value industries with deep client data repositories. Known for their association with the Conti group, SilentRansomGroup inherits some of the same attack patterns but operates independently as a distinct entity today.

Key Capabilities

  • Ransomware deployment
  • Spear-phishing with malicious links or attachments
  • Fileless malware techniques
  • Credential dumping operations
  • Persistence mechanisms

MITRE ATT&CK Tactics

Initial Access
Execution
Credential Access
Discovery
Defense Evasion

ATT&CK Techniques

T1059.003
T1566.003
T1078.001
T1203.001
T1040

Software / Tooling

Cobalt Strike (past association)
Conti malware suite (past association)
Custom ransomware
Phishing tools

Campaigns & Victims

SilentRansomGroup has conducted multiple campaigns targeting law firms and legal entities. Their operational tempo indicates a steady but not overly aggressive campaign pattern, suggesting they focus on successful extortion rather than rapidattacks. The group has targeted victims in North America and Europe, with the majority of their activity observed in the U.S. Their campaigns often involve double extortion tactics, where both data theft and encryption are employed to maximize ransom payments.

IOC Patterns

  • Spear-phishing emails with malicious links or attachments
  • Use of encrypted communication channels for C2
  • Fileless malware execution in memory
  • Ransomware payload delivery via scheduled tasks or remote scripts

Recommended Actions

  • Implement robust phishing detection and training programs.
  • Segment network access to limit lateral movement potential.
  • Encrypt sensitive data and implement air-gapped backups.
  • Monitor for unusual network activity indicative of C2 communications.
  • Conduct regular security audits to identify vulnerabilities.

Suggested Tags

Ransomware
Cybercriminal
Law Firm Targeting

Confidence Assessment

High confidence in the group's identity and targeting patterns, but limited visibility into specific tools or techniques beyond those inferred from past associations like Conti. No direct evidence of their TTPs is publicly available.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

30

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Cybercriminal
Law Firm Targeting

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Jun 7, 2022
Last Seen
Aug 7, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.