Google Mandiant researchers have identified a sophisticated extortion campaign by the threat actor UNC3753, which uses voice phishing and physical office intrusions to steal sensitive corporate data.
Key Points
- Threat actor UNC3753, also known as Silent Ransom Group, targeted U.S. financial and legal firms between January and May 2026.
- Attackers use social engineering and vishing to trick employees into installing remote monitoring software like AnyDesk or Zoho Assist.
- The group has escalated tactics to include physical office intrusions, where actors pose as IT technicians to steal data via USB drives.
- Stolen information includes proprietary legal agreements, financial records, and personally identifiable information, which are then used for extortion.
- Operations are highly efficient, often completing the entire cycle from initial contact to data exfiltration within a single business day.
- The group utilizes a resilient DNS Fast Flux network across 18 countries to host its data leak site and staging infrastructure.