DFIR Tech Blog – an AI playground

Deutsch English
Foto von Jon Tyson auf Unsplash.com

The Fake Technician at the Door: Forensics vs. Silent Ransom Group

06.08.2026 social engineeringphysical securityransomwareincident response

When Phishing Isn’t Enough: The Next Step Walks Through the Door

The Silent Ransom Group (SRG) – also tracked as Luna Moth, Chatty Spider, or UNC3753 – has been one of the most prolific data-theft extortion outfits since the collapse of Conti in 2022. SRG actors—active since at least 2022—conduct data theft and extortion operations without relying on traditional ransomware encryption. No file encryption, just fast data grabs followed by leak-site pressure.

On May 26, 2026, the FBI issued a Flash Alert documenting a striking escalation. Through phone calls and phishing emails, SRG actors pose as IT support to establish access to victim computers and exfiltrate data, usually through legitimate remote access tools or by sending an individual in-person to the victim company’s location to gain physical access to computers. When the phone-based approach fails, the group sends someone in person. “While on the phone, the SRG actor directs the employee to grant access to a remote desktop session,” the FBI said. “If that attempt fails, SRG sends a threat actor to the victim’s location to gain access and insert a storage device into the victim’s computer.”

What makes this particularly notable is that SRG doesn’t need to perform the physical visit itself. Recorded Future documented cases where the group’s solution was recruiting a gig worker through a legitimate platform to physically enter corporate offices and steal data – the gig worker was unaware they were working for hackers, believing they were performing a legitimate IT task. As Cyberscoop put it, the in-person element to the scheme “is unique and places Silent Ransom Group in a completely different mode of operation than its peers in ransomware and data theft extortion”.

The Technical Signature: From Quick Assist to the USB Stick

The digital side of the campaign is still recognizable. Mandiant describes how victims are lured into sessions where the group “impersonates IT help desks and convinces employees to join remote support sessions via Microsoft Teams, Zoom, Quick Assist, or Microsoft Terminal Services.” During these sessions, targets are tricked into installing “remote monitoring and management tools such as AnyDesk, Zoho Assist, Bomgar, or SuperOps,” thereby granting the attackers initial network access. Exfiltration itself relies on unremarkable, legitimate tooling: SRG actors use WinSCP or a hidden or renamed version of Rclone to exfiltrate data, and also exfiltrate data to internal filesharing platforms such as Google Drive or Microsoft OneDrive.

In the physical scenario, the evidentiary picture shifts entirely: by sending someone in-person to facilitate the intrusion, SRG actors exfiltrate data to an external hard drive or USB drive inserted by the threat actor into the victim’s computer. The phishing infrastructure follows a recognizable pattern as well, combining lookalike domains with disposable messaging services. Mandiant discovered phishing domains tied to the campaign that impersonate internal IT portals using naming patterns such as organization-itdesk.com, organization-it.com, organization-helpdesk.com, and the threat actors also use privnote.com, a self-destructing messaging service, to share installation links and commands with targets during remote support sessions.

Investigative Approach: Merging Physical and Digital Evidence

For DFIR teams, this case shows that endpoint forensics alone is no longer sufficient. Investigations need to correlate several layers of evidence:

Prevention has to bridge both worlds too. Among the FBI’s recommendations: verify the credentials of all individuals accessing company spaces, including obtaining copies of each visitor’s ID cards; limit access to sensitive data from less secure networks, such as home or public internet; develop and communicate policies regarding when and how IT support will communicate and authenticate themselves to employees.

For law firms and other favored targets, the lesson is clear: physical security and IT security can no longer operate in silos. Any incident response playbook that leaves out reception staff, visitor management, and facilities teams is blind to precisely the attack vector SRG is currently exploiting with success.

← Back to overview