DFIR Tech Blog – eine KI-Spielwiese

Deutsch English
Foto von Jon Tyson auf Unsplash.com

Falscher Techniker vor Ort: Forensik gegen Silent Ransom Group

06.08.2026 social engineeringphysical securityransomwareincident response

Wenn Phishing nicht reicht: Der nächste Schritt ist der Türsteher

Die Silent Ransom Group (SRG) – auch als Luna Moth, Chatty Spider oder UNC3753 bekannt – gehört seit dem Zerfall von Conti 2022 zu den produktivsten Data-Theft-Extortion-Gruppen. SRG actors—active since at least 2022—conduct data theft and extortion operations without relying on traditional ransomware encryption. Das Kerngeschäft: kein Verschlüsseln, sondern schnelles Abgreifen sensibler Daten und Erpressung mit deren Veröffentlichung.

Am 26. Mai 2026 veröffentlichte das FBI einen Flash-Alert, der eine bemerkenswerte Eskalation dokumentiert. Through phone calls and phishing emails, SRG actors pose as IT support to establish access to victim computers and exfiltrate data, usually through legitimate remote access tools or by sending an individual in-person to the victim company’s location to gain physical access to computers. Scheitert der klassische Telefon-Trick, schickt die Gruppe buchstäblich jemanden vorbei. “While on the phone, the SRG actor directs the employee to grant access to a remote desktop session,” the FBI said. “If that attempt fails, SRG sends a threat actor to the victim’s location to gain access and insert a storage device into the victim’s computer.”

Besonders bemerkenswert: Die Gruppe muss den physischen Auftritt nicht selbst durchführen. Recorded Future dokumentiert Fälle, in denen SRG schlicht recruiting a gig worker through a legitimate platform to physically enter corporate offices and steal data – the gig worker was unaware they were working for hackers, believing they were performing a legitimate IT task. Cyberscoop bringt es pointiert auf den Punkt: the in-person element to the scheme “is unique and places Silent Ransom Group in a completely different mode of operation than its peers in ransomware and data theft extortion”.

Die technische Handschrift: Von Quick Assist bis zum USB-Stick

Der digitale Teil der Kampagne bleibt erkennbar. Mandiant beschreibt, wie Opfer “impersonates IT help desks and convinces employees to join remote support sessions via Microsoft Teams, Zoom, Quick Assist, or Microsoft Terminal Services.” Anschließend werden Tools wie “remote monitoring and management tools such as AnyDesk, Zoho Assist, Bomgar, or SuperOps” installiert, wodurch die Angreifer Zugang zum Netzwerk erhalten. Für die Exfiltration greift SRG auf unauffällige, legitime Werkzeuge zurück: SRG actors use WinSCP or a hidden or renamed version of Rclone to exfiltrate data, and also exfiltrate data to internal filesharing platforms such as Google Drive or Microsoft OneDrive.

Beim physischen Szenario verschiebt sich die Beweislage vollständig: by sending someone in-person to the victim’s location to facilitate the intrusion, SRG actors exfiltrate data to an external hard drive or USB drive inserted by the threat actor into the victim’s computer. Auch die Phishing-Infrastruktur folgt einem Muster, das forensisch nutzbar ist: Domains, die interne IT-Portale imitieren, sowie der Einsatz von Wegwerf-Nachrichtendiensten. Mandiant discovered phishing domains tied to the campaign that impersonate internal IT portals using naming patterns such as organization-itdesk.com, organization-it.com, organization-helpdesk.com, and the threat actors also use privnote.com, a self-destructing messaging service, to share installation links and commands with targets during remote support sessions.

Ermittlungsansatz: Physische und digitale Spuren zusammenführen

Für DFIR-Teams bedeutet dieser Fall, dass klassische Endpunkt-Forensik nicht ausreicht. Notwendig ist die Korrelation mehrerer Beweisebenen:

Auch die Prävention muss beide Welten verbinden. Das FBI empfiehlt unter anderem, Verify the credentials of all individuals accessing company spaces, including obtaining copies of each visitor’s ID cards; Limit access to sensitive data from less secure networks, such as home or public internet; Develop and communicate policies regarding when and how IT support will communicate and authenticate themselves to employees.

Für Kanzleien und andere klassische Ziele bedeutet das: Physical Security und IT-Security können nicht länger getrennt betrieben werden. Wer den Empfang, die Besucherverwaltung und die Facility-Teams nicht in die Incident-Response-Playbooks einbezieht, übersieht genau jenen Angriffsvektor, den SRG aktuell mit Erfolg nutzt.

← Zurück zur Übersicht