Silent Threat: FBI Warns Law Firms of Luna Moth’s Sophisticated Phone Scam Targeting Your Office


# FBI Warns of Luna Moth Social Engineering Attacks Targeting Law Firms

The FBI has issued an alert about sophisticated social engineering attacks conducted by a criminal extortion group known as Luna Moth (also called Chatty Spider, Silent Ransom Group, Storm-0252, and UNC3753) that has been targeting law firms for the past two years.

## Evolving Attack Methods

Initially, Luna Moth employed callback phishing tactics, sending seemingly harmless emails about invoices or subscription payments that urged recipients to call a provided phone number to cancel premium subscriptions within 24 hours to avoid charges. During these calls, victims were guided to install remote access software, unknowingly giving attackers access to their systems.

As of March 2025, the group has shifted tactics by directly calling targets and impersonating IT department employees. The attackers convince employees to join remote access sessions, claiming that “work needs to be done overnight.” Once access is granted, they escalate privileges and use legitimate tools like Rclone or WinSCP to steal sensitive data.

## Technical Sophistication

What makes these attacks particularly dangerous is the use of legitimate system management and remote access tools such as:
– Zoho Assist
– Syncro
– AnyDesk
– Splashtop
– Atera

These legitimate applications typically bypass security detection systems. For devices without administrative privileges, the attackers deploy portable versions of WinSCP to exfiltrate data.

## Extortion Tactics

After stealing sensitive information, Luna Moth sends extortion demands, threatening to publish or sell the stolen data unless payment is made.

## Warning Signs

The FBI advises organizations to watch for:
– WinSCP or Rclone connections to external IP addresses
– Emails or voicemails from unnamed groups claiming data theft
– Subscription service emails providing phone numbers for cancellation
– Unsolicited calls from supposed IT department staff

Recent research from EclecticIQ revealed that Luna Moth has been conducting “high-tempo” phishing campaigns against U.S. legal and financial sectors using Reamaze Helpdesk and other remote desktop software. In March alone, the group registered at least 37 domains via GoDaddy, most spoofing IT helpdesk portals of targeted organizations.

Share This Article