Silent Ransom Group: Zero-Encryption Cyber Extortion

An employee takes a call from a friendly voice claiming to be internal IT. The caller is following up on an issue and finishing it should only take a few minutes. The employee cannot recall opening a ticket, and with work waiting, they download the “help tool” as instructed, approve remote access to the computer, and get back to what they were doing. The whole thing is forgotten by lunch. The first sign that anything was wrong arrives weeks later, when an unbranded email lands in a dozen executive mailboxes explaining that those files are now gone and that the company has three days to make contact before the data is released. Nothing was encrypted, no malware tripped an alert, and theft is weeks old by the time anyone knows it happened.

That is the Silent Ransom Group, which we refer to simply as Silent. Their name aptly reflects their strategy. When they strike, there are no encryption events, locked screens, or ransom notes splashed across your desktop.

Silent, which also goes by Luna Moth, Chatty Spider, and UNC3753, was one of the earliest groups to drop the encryptor and run on data theft alone.

 This was a logical evolution: Encryption had become harder to execute successfully and at scale, and inadvertent disruption of critical infrastructure had started to raise sanctions exposure that no ransomware group wanted. Working without an encryptor also changes the shape of every conversation with the victim — since there are no network outages or restoration costs to capture attention, negotiations start with the data and what the attacker believes it is worth.

We have tracked Silent since early 2022 and followed its habits, its escalation patterns, and its tactics, techniques, and procedures across that time. The operation and victimology have stayed strikingly consistent, but the technical approach has shifted slightly. 

The Phone Call is the Breach

Silent runs low-tech attacks that depend on the most critical part of the attack chain: Human interaction. Silent’s earlier methodologies followed a familiar pattern of an employee opening an inconspicuous email that was designed to look like routine billing (such as a confirmation the employee never ordered) with a support number to call to dispute the charge. The number, when called, reaches an Silent operator posing as the company’s own IT help desk or a vendor support line.

More recent attacks have started with email bombing, where the operator then calls the victim through Microsoft Teams or a similar platform, poses as the help desk, and offers to deal with the flood of spam. Most of these latest attacks involve no email at all — just a cold call from a familiar-looking number and that impersonates IT and says there is an issue they need to address.

In either case, the operator talks the employee into starting a screen-share session and installing a remote monitoring and management tool, which is the same category of software IT teams use every day. The victim then  grants the access, because as far as they can tell they are being helped. Hence the detection problem — nothing here looks like an attack because none of it is truly malware, only legitimate software operated by the wrong hands.

Quiet, Fast, and Gone

Once inside, Silent steals with ordinary tools, using WinSCP or a renamed copy of Rclone to push files out to cloud storage such as MEGA. When those tools fail, the group falls back on the most basic method available and emails the files directly to a mailbox it controls. Mandiant’s reporting on the group documents intrusions that moved from first contact, to data theft, to ransom demand in under an hour, though in the cases we work, the demand often arrives days or weeks after the session.

At that moment, Silent rapidly increases the pressure. They typically send an unbranded email with three-day deadline, threatening to sell or publish the stolen files unless demands are met. If that does not produce a fast enough response, Silent calls employees directly, and at times the victim’s own clients, to force the issue. If the ransom goes unpaid, the data is posted to a public leak site for anyone to take.

The development that earned an FBI flash report in May 2026 is an extreme but telling example of the depth of Silent’s methodology. When remote approaches stall or are impossible, Silent may send in-person operators posing as IT employees to an on-site location. With a fabricated reason to be there, they plug a storage device directly into sensitive systems to copy data.

Why It Pays, and What Paying Buys

Since the spring of 2023, Silent’s primary targets have been U.S. law firms and insurance companies. The reasoning is cold and correct: Privileged legal data carries severe exposure, and severe exposure supports a large demand, with reported demands reaching $20 million. A firm facing the publication of client confidences with bar obligations and breach-notification laws bearing down has every incentive to pay quietly and fast. With these victims, a single document can be enough to push the perceived value well into seven figures.

This is where extortion is heading. It matches what our caseload has shown for the past year: Indiscriminate, bulk smash-and-grab exfiltration is fading, and precise, social-engineered theft aimed at high-value targets has taken its place. Silent is the clearest template for that shift.

With no encryption, there is no key to buy back, and once recovery is off the table, the negotiation has fewer variables in play, so the tempo and tone of the conversation shift to the data and nothing else.

A victim who pays Silent is paying for a single thing: A promise to delete the stolen data. That promise, however, is completely unverifiable. There is no way to confirm that a copy was not kept, sold, or held back for a second attempt months later. A screenshot of an empty folder proves nothing.

We see with market trends that exfiltration-only attacks converted to payment just 19% of the time in our Q3 2025 data, a record low at the time, and 15% of the time in Q2 2026. Against a leak-only group, a payment is a bet on the honesty of an extortionist, or a belief in honor among thieves, which turns the decision to legal and regulatory exposure since the business was never knocked offline to begin with.

What Actually Stops It

Silent took the malware out of ransomware and still sees success — because encryption was never the point, and for this group, data was always the asset.

In preparation, organizations must:

  • Verify identity on any inbound IT contact, enforce out-of-band callback procedures, and train staff on the fact that real IT will not cold-call asking for a remote session.
  • Restrict and alert on RMM tool installation, since most environments run one or two sanctioned tools and an unexpected one is a loud signal.
  • Watch outbound traffic for the utilities and destinations Silent favors, including large transfers to consumer cloud storage.
  • Shrink what any single compromised session can reach, so that when someone does talk their way in, the size of the theft is capped by design.
  • Implement and reinforce the FBI’s baseline that multi-factor authentication (MFA) is used for every employee, along with strong and unique passwords and steady training against social engineering.

The defenses that matter against Silent sit upstream of any backup or endpoint product, because the attack never touches the things those products watch. The control surface is the people.

For the underlying numbers on exfiltration-only extortion, payment rates, and attack vectors, read the latest edition of Cyber Extortion Review.

The post Silent Ransom Group: Zero-Encryption Cyber Extortion appeared first on Veeam Software Official Blog.

from Veeam Software Official Blog https://ift.tt/6ybVt4Z

Share this content: