FBI Flags Silent Ransom Group's Physical Intrusion Tactic Against U.S. Law Firms
The threat actor known as Silent Ransom Group has added walk-in impersonation to its toolkit, sending actors posing as IT support into law firm offices to insert storage devices into employee computers.

The FBI issued a Flash report this week detailing a shift in tactics by a data-theft and extortion gang it designates the Silent Ransom Group — also tracked by researchers under the names Luna Moth, Chatty Spider, and UNC3753. The group, active in data theft and extortion operations since at least 2022, does not deploy ransomware encryption. It steals data, then demands payment under threat of public disclosure or sale.
The new wrinkle is physical access.
Since spring 2025, SRG actors have posed as IT department employees, contacting firm staff by phone or phishing email to prompt a call to a fake support line. On that call, they request a remote desktop session. When that fails, the bureau says, they send someone in person — walking into the victim's office and inserting a storage device into a computer under the pretext of imaging the drive or creating a backup related to the original phishing email.
The bureau's Flash report lists specific indicators of compromise to watch for: unauthorized installation of remote access tools including Zoho Assist, AnyDesk, RustDesk, Syncro, Splashtop, and Atera; unauthorized USB or external hard drive connections; WinSCP or Rclone connections to external IP addresses; and data exfiltration to Microsoft OneDrive, Google Drive, or external servers. The group uses WinSCP or a hidden or renamed Rclone binary to move data out. Privilege escalation is described as minimal — the actors pivot quickly to exfiltration once access is established.
Security practitioners the FBI consulted for context noted the physical vector is not new conceptually. Roger Grimes, a CISO advisor at KnowBe4, said walk-in USB attacks have been common enough in banking that the sector has routinely included physical attacker scenarios in penetration testing audits for years. Lance Spitzner of the SANS Institute characterized the in-person approach as relatively rare among cyber threat actors, noting the personal exposure it requires, and speculated the group may be using paid insiders or contractors to reduce that risk.
The FBI is still collecting evidence on the frequency of successful physical visits and has asked recipients to preserve extortion notes, phone numbers, email accounts, communications transcripts, and any surveillance footage of individuals posing as IT staff.
For law firms, the risk profile is specific. Those environments hold privileged communications, client financial data, and active case strategy — material that does not lose value after initial theft. Extortion pressure can extend outward to clients, not just the breached firm itself.
The immediate training priorities the bureau identifies are two: employees must verify any unsolicited contact claiming to be IT support through a pre-approved internal channel — not by replying to the message or calling a number provided in it — and must treat unannounced physical visitors claiming IT roles as unverified until confirmed. Organizations using third-party IT providers face additional exposure, since employees may not recognize their own legitimate support staff on sight.
The FBI has not publicly released the underlying Flash report document number as of publication.



