AUTO-UPDATED

UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign

Google Mandiant researchers have identified a sophisticated extortion campaign by the threat actor UNC3753, which uses voice phishing and physical office intrusions to steal sensitive corporate data.

Key Points

  • Threat actor UNC3753, also known as Silent Ransom Group, targeted U.S. financial and legal firms between January and May 2026.
  • Attackers use social engineering and vishing to trick employees into installing remote monitoring software like AnyDesk or Zoho Assist.
  • The group has escalated tactics to include physical office intrusions, where actors pose as IT technicians to steal data via USB drives.
  • Stolen information includes proprietary legal agreements, financial records, and personally identifiable information, which are then used for extortion.
  • Operations are highly efficient, often completing the entire cycle from initial contact to data exfiltration within a single business day.
  • The group utilizes a resilient DNS Fast Flux network across 18 countries to host its data leak site and staging infrastructure.

Why it Matters

This campaign highlights a dangerous shift toward human-centric attacks that bypass traditional technical security perimeters like multi-factor authentication. By exploiting trust through social engineering and physical presence, these actors force organizations to confront significant reputational and regulatory risks in a very short timeframe.
Internet Published by info@thehackernews.com (The Hacker News)
Read original