Silent Ransom Group Uses IT Impersonation and Physical Access to Breach US Law Firms (infosecurity-magazine.com)
- SRG uses phone calls and in-person visits to impersonate IT support, tricking victims into granting remote access or inserting USB drives.
- Data exfiltration is done via WinSCP, Rclone, or direct USB copy, without encryption, making detection difficult.
- FBI recommends multi-factor authentication, visitor ID checks, and disabling port 22 to mitigate attacks.
"Threat actors from the Silent Ransom Group (SRG), also known as Luna Moth, are escalating attacks by impersonating IT staff over the phone and in person. According to an FBI Flash Alert from May 2026, the group has targeted US law firms since 2023, now using social engineering to gain remote desktop access or sending actors to physically insert storage devices. Once inside, they exfiltrate data using legitimate tools like WinSCP or Rclone, without encryption. The FBI recommends multi-factor authentication, visitor verification, and blocking port 22 where possible."
aucun commentaire pour l'instant.