The FBI has issued an alert about sophisticated social engineering attacks conducted by a criminal extortion group known as Luna Moth (also called Chatty Spider, Silent Ransom Group, Storm-0252, and UNC3753) that has been targeting law firms for the past two years.
## Evolving Attack Methods
Initially, Luna Moth employed callback phishing tactics, sending seemingly harmless emails about invoices or subscription payments that urged recipients to call a provided phone number to cancel premium subscriptions within 24 hours to avoid charges. During these calls, victims were guided to install remote access software, unknowingly giving attackers access to their systems.
As of March 2025, the group has shifted tactics by directly calling targets and impersonating IT department employees. The attackers convince employees to join remote access sessions, claiming that “work needs to be done overnight.” Once access is granted, they escalate privileges and use legitimate tools like Rclone or WinSCP to steal sensitive data.
## Technical Sophistication
What makes these attacks particularly dangerous is the use of legitimate system management and remote access tools such as:
– Zoho Assist
– Syncro
– AnyDesk
– Splashtop
– Atera
These legitimate applications typically bypass security detection systems. For devices without administrative privileges, the attackers deploy portable versions of WinSCP to exfiltrate data.
## Extortion Tactics
After stealing sensitive information, Luna Moth sends extortion demands, threatening to publish or sell the stolen data unless payment is made.
## Warning Signs
The FBI advises organizations to watch for:
– WinSCP or Rclone connections to external IP addresses
– Emails or voicemails from unnamed groups claiming data theft
– Subscription service emails providing phone numbers for cancellation
– Unsolicited calls from supposed IT department staff
Recent research from EclecticIQ revealed that Luna Moth has been conducting “high-tempo” phishing campaigns against U.S. legal and financial sectors using Reamaze Helpdesk and other remote desktop software. In March alone, the group registered at least 37 domains via GoDaddy, most spoofing IT helpdesk portals of targeted organizations.
