The Silent Ransom Group (SRG), a pure data exfiltration and extortion actor known for previously targeting law firms with callback phishing campaigns, has recently been using a different social engineering ploy, a new FBI Flash alert warns.

The attackers have started posing as IT teams via phone calls and phishing emails sent to legal sector firms. The end goal is exfiltrating data from victims’ computers for extortion, and threat actors are using several different ways to do so. They may use legitimate remote access tools (like Zoho Assist, Quick Assist, or AnyDesk). But in some cases, they’ve even sent an individual in-person to the victim company’s location to gain physical access to computers, according to the FBI on Tuesday.

“SRG actors… conduct data theft and extortion operations without relying on traditional ransomware encryption,” according to the FBI. “Unlike conventional ransomware actors, SRG actors typically seek rapid access to victim systems, immediate data exfiltration, and extortion through threats of public disclosure or sale of stolen data.”

The threat actors have consistently targeted US-based law firms since Spring 2023, according to the FBI. However, their TTPs have changed. Previously, SRG actors used phishing emails with “subscription fee” lures to gain access to victim networks. Victims would be instructed to call the threat actor in order to cancel the fake subscription. The attacker then emailed them a link to download remote access software.

Starting this Spring, the actors are now posing as an employee from the victim’s IT department. 

“SRG actors either directly call or send phishing emails to urge employees to call the SRG actor posing as IT support,” according to the FBI. “While on the phone, the SRG actor directs the employee to grant access to a remote desktop session. If that attempt fails, SRG sends a threat actor to the victim’s location to gain access to insert a storage device into the victim’s computer. In this scheme, the threat actor tells the victim they need to image the device or create a backup file to address potential impacts from the phishing email.”

After compromising victim devices, the threat actors pivot rapidly to exfiltration using open source tools like Windows Secure Copy (WinSCP), a free file manager and transfer application, or renamed versions of Rclone, a command-line program that manages and syncs files across cloud storage providers. 

Unlike actual ransomware attacks, the threat actors skip encryption, instead using exfiltrated victim data to extort the victim with a ransom note. In some cases, the attackers have called victim employees or even clients to add pressure in ransom negotiations. 

SRG has been active since 2022. They are reportedly former Conti ransomware syndicate operators, and are known by other aliases like Luna Moth, Chatty Spider, and UNC3753. This is only SRG’s latest evolution; in March 2025, they switched over to “aggressive direct vishing campaigns assessed as highly effective,” according to Halcyon.