Full Report
In leaked chats, members track dozens of victims, haggle over multimillion-dollar payments and direct operatives based in the United States whom they call “agents.”
Analysis Summary
# Incident Report: Physical Infiltration & Extortion by Silent Ransom Group
## Executive Summary
A Russia-based cyberextortion gang, identified as Silent Ransom Group (Luna Moth/Chatty Spider), utilized a hybrid attack model involving the recruitment of U.S.-based "agents" to physically infiltrate law firms and corporate offices. Leaked internal chats reveal a sophisticated operation that combined digital extortion with physical data theft via USB devices, targeting high-value victims for multimillion-dollar ransoms. The incident highlights an escalating trend of merging traditional cybercrime with physical espionage tactics.
## Incident Details
- **Discovery Date:** Early October 2026 (via leaked chat archive)
- **Incident Date:** August 2025 – September 2026
- **Affected Organization:** Multiple U.S. law firms and businesses (specific names withheld in summary)
- **Sector:** Legal / Professional Services
- **Geography:** United States (New York, Chicago) and Russia (Threat Actors)
## Timeline of Events
### Initial Access
- **Date/Time:** Ongoing throughout late 2025 and 2026.
- **Vector:** Physical Infiltration / Social Engineering.
- **Details:** Attackers recruited local operatives via Telegram job ads. These "agents" entered offices posing as IT personnel, delivery workers (pizza ruse), or clients.
### Lateral Movement
- **Details:** Once physically inside, agents accessed workstations or server rooms to bypass perimeter network defenses.
### Data Exfiltration/Impact
- **Details:** Files were copied directly onto physical flash drives. In one instance, a New York law firm confirmed an individual successfully copied sensitive files via a USB device.
### Detection & Response
- **How it was discovered:** Internal security footage/staff observation of unauthorized physical access; subsequent extortion demands; and a leak of the group’s internal Telegram chats on a .onion site in October 2026.
- **Response actions taken:** The FBI issued a flash alert warning law firms of the group's tactics. Impacted firms engaged in ransom negotiations, with one firm offering $1 million to settle.
## Attack Methodology
- **Initial Access:** Physical breach (impersonating IT/couriers).
- **Persistence:** Not explicitly stated, though physical access allows for the potential planting of hardware backdoors.
- **Privilege Escalation:** Physical access to unlocked or poorly secured workstations.
- **Defense Evasion:** Use of local "disposable" agents to mask Russian origin; wearing disguises (uniforms/masks).
- **Credential Access:** Likely obtained via physical observation or locally installed keyloggers (implied by physical access).
- **Discovery:** Use of "smart glasses" to record office layouts; procurement of holographic materials for forged IDs.
- **Lateral Movement:** Physical movement through the office space to locate sensitive data hubs.
- **Collection:** Manual copying of data to USB flash drives.
- **Exfiltration:** Physical removal of storage media from the premises.
- **Impact:** Extortion/Ransomware; threat of public data leak.
## Impact Assessment
- **Financial:** Demands reached multimillion-dollar levels ($1M+ per victim).
- **Data Breach:** High-volume theft of sensitive legal and corporate records.
- **Operational:** Disruption due to security lockdowns and forensic investigations.
- **Reputational:** High risk, particularly for law firms whose client confidentiality was compromised.
## Indicators of Compromise
- **Network indicators:** N/A (Focus was physical).
- **File indicators:** Unauthorized use of USB mass storage devices.
- **Behavioral indicators:** Unscheduled IT maintenance visits; delivery personnel attempting to access non-public areas; unusual Telegram job listings for "couriers" or "security" targeting Russian speakers.
## Response Actions
- **Containment:** FBI Flash Alert issued to the legal sector.
- **Eradication:** Review of physical security protocols and access badge logs.
- **Recovery:** Negotiation with threat actors (in some cases) and forensic analysis of affected workstations.
## Lessons Learned
- **Cyber-Physical Convergence:** Traditional network security is insufficient if physical access controls are weak.
- **Recruitment Sophistication:** Threat actors are now using "gig economy" models (Telegram ads) to recruit unwitting or low-level accomplices for domestic operations.
- **Negotiation Risks:** Even if ransoms are paid, there is no guarantee of data deletion (referencing the LockBit precedent).
## Recommendations
- **Physical Security:** Implement strict visitor management and multi-factor authentication for physical office entry.
- **Hardware Controls:** Disable USB ports or implement strict "Device Control" policies via Endpoint Detection and Response (EDR) tools.
- **Personnel Training:** Train staff to challenge unescorted visitors and verify IT service appointments through official channels.
- **Identity Verification:** Use advanced ID verification for all third-party contractors and deliveries.