惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

B
Blog RSS Feed
量子位
Recent Announcements
Recent Announcements
T
The Blog of Author Tim Ferriss
美团技术团队
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Blog — PlanetScale
Blog — PlanetScale
H
Help Net Security
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - Franky
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
宝玉的分享
宝玉的分享
大猫的无限游戏
大猫的无限游戏
V
Visual Studio Blog
博客园 - 聂微东
aimingoo的专栏
aimingoo的专栏
Microsoft Security Blog
Microsoft Security Blog
U
Unit 42
J
Java Code Geeks
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
IT之家
IT之家
Hugging Face - Blog
Hugging Face - Blog
腾讯CDC
L
LangChain Blog

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! Hackers Use Rokarolla Android Malware to Disable Google Play Protect and Control Devices New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users
UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exf...
Tushar Subhra Dutta · 2026-06-17 · via Cyber Security News

A sophisticated cybercriminal group has been quietly targeting law firms and professional services organizations across the United States since the beginning of 2026.

The campaign is financially motivated and relies heavily on deception rather than technical exploits. Victims are manipulated into handing over access to their own systems, and by the time they realize what happened, their most sensitive data is already gone.

The threat cluster behind these attacks, known as UNC3753, has also been tracked under the names “Luna Moth,” “Chatty Spider,” and “Silent Ransom Group.”

The group has been active since at least March 2022 and has a long history of pivoting its tactics to stay effective.

From January through May 2026, dozens of organizations in the legal, financial, and professional services sectors were targeted in what appears to be one of the group’s most active and damaging periods yet. Analysts from Google Cloud identified and documented this campaign in detail.

According to Google Cloud report shared with Cyber Security News (CSN), Google’s Threat Intelligence Group noted that the entire attack sequence, from the first phone call to completed data theft, often happened within a single business day. In some cases, the data was staged and stolen in under an hour.

The group begins each attack by sending a benign-looking invoice-themed email from a consumer email account. The message contains no malicious links or attachments.

Its only purpose is to put the target on edge so they are more likely to engage when the threat actors call shortly after, posing as internal IT helpdesk staff.

UNC3753 attack lifecycle (Source - Google Cloud)
UNC3753 attack lifecycle (Source – Google Cloud)

Once on the phone, the attackers convince the target to join a screen-sharing session and download remote monitoring and management tools.

After gaining control, the attackers search corporate file systems for high-value documents including legal agreements, tax forms, Social Security numbers, and financial records.

They then upload the stolen files to cloud accounts they control. Shortly after exiting the environment, the group sends aggressive extortion emails demanding a response within three days or threatening to notify employees, clients, and journalists about the breach.

Once a victim is on a call with the attacker, they are directed to launch a screen-sharing session through tools like Zoom, Microsoft Teams, or Quick Assist.

In one documented case, an attacker held five separate calls with the same person over three days.

From there, the group pushes the target to install commercial remote management software such as AnyDesk, Bomgar, or Zoho Assist, giving the attackers persistent access to the machine.

To avoid leaving traces, the group uses privnote.com, a self-destructing message service, to send download links and commands.

LEAKEDDATA DLS (Source - Google Cloud)
LEAKEDDATA DLS (Source – Google Cloud)

Once inside a virtual desktop environment, attackers crawl network drives, search document management platforms like iManage using specific keywords, and stage the results in the user’s Downloads folder.

Files are then uploaded through WinSCP, Rclone, or directly through the victim’s own web browser into attacker-controlled cloud storage accounts.

In one particularly aggressive incident, the group exfiltrated 1.7 gigabytes from a target’s OneDrive folder to an external account, then pivoted to a virtual desktop session and pulled an additional 14.4 gigabytes using WinSCP.

The stolen data was later threatened to be published on a data leak site called LEAKEDDATA if the victim refused to pay.

Physical Intrusions Mark a Dangerous Escalation

Beyond digital attacks, there are instances where individuals posing as IT technicians physically entered corporate offices to steal data using USB drives.

According to an FBI Cyber FLASH Alert cited in the report, if remote social engineering fails, the group sends a person on-site who claims to need physical access to address a security issue.

This physical escalation is particularly alarming because most office environments rely solely on basic administrative checks to control entry.

Google’s Threat Intelligence Group recommends that organizations conduct targeted awareness training around these specific tactics. Firms should also enforce strict physical access policies, requiring photo identification and escorted entry for all external technical visitors.

On the digital side, only corporate-owned devices should be permitted to access virtual desktops or VPNs, and unauthorized remote management tools should be blocked outright.

Real-time alerts should be configured in document management platforms to flag bulk file searches and mass downloads.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
IPv4 Address192.236.147.131Actor-controlled infrastructure
IPv4 Address192.236.147.138Actor-controlled infrastructure
IPv4 Address193.141.60.212Actor-controlled infrastructure
IPv4 Address192.236.154.158Actor-controlled infrastructure
IPv4 Address192.236.146.173Actor-controlled infrastructure
IPv4 Address174.169.162.62Actor-controlled infrastructure
IPv4 Address64.94.84.97Actor-controlled infrastructure
Domain Pattern<organization>-itdesk[.]comPhishing/vishing support domain
Domain Pattern<organization>-it[.]comPhishing/vishing support domain
Domain Pattern<organization>-helpdesk[.]comPhishing/vishing support domain
Data Leak Sitehxxps[:]//business-data-leaks[.]comUNC3753 victim disclosure platform

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.