UNC3753 (Luna Moth / Silent Ransom Group) — Vishing Data-Theft Extortion

A financially-motivated, ex-Conti cluster that calls employees posing as IT/help-desk, talks them into a screen-share or installing a remote-access tool, then searches, stages, and exfiltrates data — often in under an hour — and extorts (no encryption). 2026 escalations added physical office intrusions. Defensive hunt & harden pack — the front line here is people + RMM governance.
Threat
UNC3753 · Luna Moth · Silent Ransom Group · Chatty Spider · Storm-0252
Severity
DATA-THEFT EXTORTION · FAST
Type
Vishing / social engineering → RMM → exfil → extortion
Targets
US legal, financial & professional-services firms
Speed
Call → theft in < 1 business day (often < 1 hour)
Version
v0.5 · 2026-06-29
Author
HuntPack
01

Executive Summary

UNC3753 (a.k.a. Luna Moth, Silent Ransom Group / SRG, Chatty Spider, Storm-0252) is a financially-motivated data-theft-extortion cluster that traces back to the defunct Conti gang (overlapping UNC2686's 2021 BazarCall campaigns). It deployed LockBit Black in 2022, then dropped ransomware entirely in favour of pure data theft and extortion. From January through May 2026 (Mandiant), it targeted dozens of US legal, financial, and professional-services firms.

The tradecraft is human, not malware-led. Campaigns open with benign, invoice-themed emails designed to prompt a security worry, then a follow-up phone call (vishing) in which the caller poses as internal IT/help-desk or security and walks the target into a screen-share (Zoom, Microsoft Teams, Microsoft Terminal Services/RDP, Quick Assist) or installing a remote-access / RMM tool. With hands-on access the actor searches, stages, and exfiltrates files — often within a single business day, sometimes under an hour — then issues an aggressive extortion demand (~30 minutes after exfil, three-day deadline). 2026 saw escalation to physical intrusions: people posing as IT technicians exfiltrating via USB.

Defender priority: Because there's little custom malware, the signals are legitimate-tool abuse on a compressed timeline: Q1 (a remote-access/RMM tool installed/run shortly after a help-desk-style screen-share), and Q3 (rapid mass file staging + cloud exfil). Given the <1-hour speed, these should be high-priority real-time alerts, paired with user awareness on "IT will never cold-call you to install software."

02

Source Review & Web Hunter Notes

TierSourceKey FindingCarry
1 · Vendor researchMandiant / GTIG — UNC3753 vishing & data theft (Jan–May 2026)Invoice lure → vishing → screen-share/RMM → exfil; physical-access escalation; Conti lineageyes
1 · News of recordThe Hacker News / BleepingComputerLaw-firm targeting; fake IT-support calls; RMM exfil; speedyes
1 · Gov advisoryFBI Flash (TLP:Clear) — Silent Ransom GroupSRG impersonating IT through social engineering; remediation guidanceyes
2 · VendorRescana / Dark Reading / Security AffairsRemote-access tooling, <1hr exfil, 3-day extortion, screen-share apps usedyes

Decisions: behavior-first on legitimate-tool abuse (no custom malware to signature); anchor on RMM-after-screenshare + rapid exfil; emphasize people/process controls (help-desk verification, RMM governance) since the entry point is a phone call; flag the compressed timeline as requiring real-time alerting.

03

Hunt Brief & Attack Chain

Working hypothesis: An employee receives an invoice-themed email, then a vishing call; they grant a screen-share or install a remote-access tool; the actor rapidly searches, stages, and exfiltrates files, then extorts.

StepBehaviorTelemetryHunt Angle
1 · LureBenign invoice-themed email; callback numberMail gatewayN1
2 · VishingCaller poses as IT; directs to screen-share / tool install(phone — off-platform)User reporting
3 · AccessScreen-share (Zoom/Teams/Quick Assist/RDP) or RMM installProcessRollup2Q1 / Q2
4 · Find & stageRapid file search/enumeration; archive stagingProcessRollup2; fileQ4
5 · ExfilRclone/WinSCP/cloud upload — within the hourNetworkConnectIP4Q3
5b · PhysicalFake IT tech on-site; USB mass-copyUSB / file eventsQ5
6 · ExtortionDemand ~30 min later; 3-day deadline (no encryption)(email/phone)IR / legal

Affected surface & telemetry

SurfaceRequired TelemetryPriorityGap Risk
Windows user endpointsProcess lineage + command line (ProcessRollup2)CriticalLow — standard sensor
Remote-access toolsProcess/service install; software inventoryCriticalLow — reliable
Data exfilMass file access; cloud-upload / Rclone egress; DLPHighMedium — needs DLP/egress visibility
USB (physical variant)Removable-media + mass-copy eventsMediumMedium — USB auditing
04

Consolidated IOC Table

There's almost no custom malware — the "indicators" are legitimate tools used in an illegitimate context on a compressed timeline. Copy-ready blocks in §9.
TypeValueConfActionContext
Behaviorremote-access/RMM tool installed shortly after a screen-share sessionhighdetectVishing-granted access — flagship
BehaviorQuick Assist (quickassist.exe) initiated by an end usermediumhuntCommon screen-share vector
Behaviorrapid mass file enumeration + archive staging within the hourhighdetectSearch-and-stage
BehaviorRclone / WinSCP / cloud upload of staged datahighdetectExfil
BehaviorUSB mass-copy (physical-access variant)mediumhuntOn-site exfil
05

ATT&CK Mapping

TacticTechniqueObserved BehaviorQuery / Control
Initial AccessT1566.004 / T1598 — Phishing voice / spearphishing for infoInvoice lure + vishing callN1; user training
Initial Access / C2T1219 — Remote Access SoftwareScreen-share / RMM install (Quick Assist, AnyDesk, ScreenConnect, Zoho, Splashtop)Q1, Q2; N2
CollectionT1083 / T1074 — File discovery / stagingRapid search + archive stagingQ4
ExfiltrationT1567.002 / T1048 — Exfil to cloud / over webRclone / WinSCP / cloud uploadQ3; N4
ExfiltrationT1052.001 — Exfil over USB (physical)On-site USB mass-copyQ5
ImpactT1657 — Financial theft / extortionExtortion demand (no encryption)IR / legal
06

Native Audit-Log Hunts

HuntSourceLogicResponse
N1 · Invoice-lure emailMail gatewayBenign invoice-themed emails with callback phone numbers (no link/attachment) to many usersWarn users; brief the help desk
N2 · Unsanctioned RMMSoftware inventory / service installAnyDesk/ScreenConnect/Zoho/Splashtop/Atera/Quick Assist used outside sanctioned IT supportInvestigate; uninstall; isolate
N3 · Mass file accessFile-audit / DLPA user account touching/staging unusually many files in a short windowVerify with the user; isolate on confirm
N4 · Exfil egressProxy / CASB / firewallLarge upload to a cloud-storage / file-transfer service shortly after remote-accessBlock; preserve; notify DPO
N5 · USB mass-copyRemovable-media audit (EID 4663 / DLP)Large volume of files copied to removable media (physical-access variant)Physical-security + IR response
07

CrowdStrike LogScale CQL Hunt Queries

Pick your tenant's cloud first — every "Open in Falcon" button below uses this selection.
Field names validated against the Falcon event reference; process hunts include SyntheticProcessRollup2. Given the <1-hour speed, run Q1/Q3 as real-time scheduled detections. If RMM tools are sanctioned, allow-list the IT host group + managed deploy.
Q1 · Remote-access / RMM tool execution (unsanctioned)
CONF HIGHFP MEDCOST LOW

Looks for: the remote-access tools UNC3753 favours, on hosts outside sanctioned IT support. Accomplishes: the vishing-granted access — flagship. FP: sanctioned RMM — allow-list IT host group + managed deploy.

// HUNT: UNC3753 remote-access/RMM (unsanctioned screen-share/control tool)
// MITRE: T1219 | CONF: high  FP: medium  COST: low
// TUNING: allow-list sanctioned RMM + the IT-support host group
#event_simpleName=/ProcessRollup2|SyntheticProcessRollup2/
| FileName=/^(AnyDesk|ScreenConnect|Connectwisecontrol|ZohoAssist|Zaservice|Splashtop|SRService|TeamViewer|AteraAgent|syncro|LogMeIn|RustDesk)[^\\]*\.exe$/i
| table([@timestamp, ComputerName, UserName, FileName, ImageFileName, CommandLine, ParentBaseFileName], limit=200)
Q2 · Quick Assist / RDP screen-share initiated by an end user
CONF MEDFP MEDCOST LOW

Looks for: quickassist.exe launched by a standard user (the common vishing screen-share). Accomplishes: the access-grant vector. FP: legit IT-assisted sessions — correlate with a following Q3/Q4.

// HUNT: UNC3753 Quick Assist screen-share (user-initiated)
// MITRE: T1219 | CONF: medium  FP: medium  COST: low
// TUNING: correlate to a following exfil (Q3) / mass file access (Q4)
#event_simpleName=/ProcessRollup2|SyntheticProcessRollup2/
| FileName=/^(quickassist|msra)\.exe$/i
| table([@timestamp, ComputerName, UserName, FileName, CommandLine, ParentBaseFileName], limit=200)
Q3 · Rapid exfil — Rclone / WinSCP / cloud upload
CONF HIGHFP LOW-MEDCOST LOW

Looks for: exfil tooling (rclone, WinSCP) or cloud-upload command lines. Accomplishes: the data-theft stage — escalate immediately. FP: sanctioned backup/sync — allow-list known jobs.

// HUNT: UNC3753 rapid exfil (Rclone / WinSCP / cloud upload)
// MITRE: T1567.002, T1048 | CONF: high  FP: low-med  COST: low
// TUNING: allow-list sanctioned backup/sync jobs; flag user-context exfil after remote-access
#event_simpleName=/ProcessRollup2|SyntheticProcessRollup2/
| (FileName=/^(rclone|winscp|filezilla|megasync|pcloud)\.exe$/i
   or CommandLine=/(rclone\s+(copy|sync|move)|mega\.nz|put\s+.+\.zip|--no-check-certificate.*upload)/i)
| table([@timestamp, ComputerName, UserName, FileName, CommandLine], limit=200)
Q4 · Mass file enumeration + archive staging
CONF MEDFP MEDCOST LOW

Looks for: archive tooling (7-Zip/WinRAR) staging large data, or scripted file enumeration, shortly after a remote-access session. FP: legit archiving — correlate with Q1/Q2 + Q3.

// HUNT: UNC3753 search-and-stage (archive staging / file enumeration)
// MITRE: T1083, T1074 | CONF: medium  FP: medium  COST: low
// TUNING: correlate to a same-host Q1/Q2 within the prior hour
#event_simpleName=/ProcessRollup2|SyntheticProcessRollup2/
| (FileName=/^(7z|7zG|WinRAR|Rar)\.exe$/i and CommandLine=/\b(a|u)\b.+\.(7z|zip|rar)/i)
   or CommandLine=/Get-ChildItem.+-Recurse.+(\.docx?|\.pdf|\.xlsx?)|forfiles\s+\/s/i
| table([@timestamp, ComputerName, UserName, FileName, CommandLine], limit=200)
Q5 · USB mass-copy (physical-access variant)
CONF MEDFP MEDCOST MED

Looks for: a burst of file writes to removable media. Accomplishes: the on-site exfil variant. FP: legit USB use — flag breadth + after-hours / unusual host. Requires removable-media telemetry.

// HUNT: UNC3753 on-site USB exfil (mass copy to removable media)
// MITRE: T1052.001 | CONF: medium  FP: medium  COST: med
// REQUIRES: removable-media telemetry
// TUNING: flag breadth + unusual host/time
#event_simpleName=/PeFileWritten|NewExecutableWritten|DcUsbDeviceConnected/
| (IsOnRemovableDisk=true or TargetFileName=/^[D-Z]:\\/i)
| groupBy([aid, ComputerName, UserName], function=[count(field=TargetFileName, distinct=true, as=files)])
| files>=50
| sort(files, order=desc)
Q6 · Outbound from a freshly-installed remote-access tool
CONF MEDFP MEDCOST MED

Looks for: outbound connections from the remote-access binaries (the operator's live session). FP: sanctioned RMM — correlate with Q1 + a non-IT host.

// HUNT: UNC3753 remote-access session egress
// MITRE: T1219 | CONF: medium  FP: medium  COST: med
// TUNING: correlate to Q1; exclude sanctioned RMM gateways
#event_simpleName=NetworkConnectIP4
| ContextBaseFileName=/^(AnyDesk|ScreenConnect|ZohoAssist|Splashtop|RustDesk|TeamViewer)[^\\]*\.exe$/i
| RemoteAddressIP4!=/^(10\.|192\.168\.|172\.(1[6-9]|2[0-9]|3[01])\.|169\.254\.|127\.)/
| table([@timestamp, ComputerName, ContextBaseFileName, RemoteAddressIP4, RemotePort], limit=200)
08

CrowdStrike Custom IOA Recommendations

IOA NameField PatternsBenign ExclusionsDeployment Path
UNC3753 — unsanctioned remote-access toolImage matches AnyDesk/ScreenConnect/Zoho/Splashtop/RustDesk outside the sanctioned host groupSanctioned RMM + IT-support hostsEndpoint Security → Custom IOA → Process Creation
UNC3753 — exfil after remote-accessRclone/WinSCP/cloud-upload within N minutes of an RMM/Quick Assist hit on the same hostSanctioned backup/sync jobsNG-SIEM correlation rule (real-time)
Q1 is a strong promotion (with allow-lists). The Q1→Q3 correlation (RMM then exfil within the hour) is the highest-value real-time detection. Q2/Q4/Q5/Q6 stay correlated hunts.
09

Machine-Readable IOC Appendix

Grouped IOC Quick-Copy

One-click blocks for detection, RMM governance, and the human-layer playbook. The "IOCs" are legitimate tools + behaviors; the front line is people + process.

Remote-Access Toolsgovern / allow-list
# Tools UNC3753 talks victims into installing/using:
AnyDesk · ScreenConnect (ConnectWise Control) · Zoho Assist · Splashtop · RustDesk
TeamViewer · LogMeIn · Atera · Syncro · Microsoft Quick Assist (quickassist.exe)
Screen-share via: Zoom · Microsoft Teams · Microsoft Terminal Services / RDP
# Maintain a single sanctioned RMM; alert on ALL others outside the IT-support fleet
Behavioral Signaturescompressed timeline
Unsanctioned remote-access tool installed/run shortly after a screen-share session
quickassist.exe initiated by a standard user (vishing screen-share)
Mass file enumeration + 7z/WinRAR archive staging within ~1 hour of remote-access
Rclone copy/sync, WinSCP, or large cloud upload of staged data (exfil)
Burst of file copies to removable media (physical-access variant, >=50 files)
Outbound from a fresh AnyDesk/ScreenConnect/RustDesk session on a non-IT host
Human-Layer Playbookthe real front line
# The entry point is a phone call - controls must be human + process:
1. Policy: IT NEVER cold-calls to install software or request a screen-share - verify via a
   known internal number / ticket before granting ANY remote access
2. Help-desk callback verification; out-of-band identity checks
3. Brief reception/security on fake "IT technician" on-site visits (physical variant)
4. Report any "invoice problem / security alert" call to the SOC immediately
# Lineage: ex-Conti (UNC2686 BazarCall); dropped ransomware -> pure data-theft extortion
Hardening / Blockdeny & restrict
WDAC/AppLocker: allow ONE sanctioned RMM; deny all others (AnyDesk/ScreenConnect/etc.)
Restrict / disable Microsoft Quick Assist for standard users (GPO) unless required
Block standard-user software installs; egress control on cloud-storage uploads
DLP on mass file access + outbound; USB write control (physical variant)
MFA everywhere; help-desk verification SOP; rapid session-revocation runbook
10

Hardening — Tiered & Deployable

The entry point is a phone call — controls are mostly human + RMM governance, backed by exfil control.

Immediate — Govern remote access & verify callers
  • WDAC/AppLocker: sanction ONE RMM tool; deny all othersM1038 / M1042. Directly defeats Q1.
  • Restrict/disable Quick Assist for standard users (GPO)M1042. Removes the common screen-share vector (Q2).
  • Help-desk verification policy: IT never cold-calls to install software / screen-share — verify out-of-bandM1017. Kills the social-engineering entry.
  • Egress / CASB control on cloud-storage uploads; DLP on mass file accessM1057 / M1037. Catches the exfil (Q3).
Near term — Restrict & observe (pilot first)
  • Block standard-user software installs; alert on any RMM outside ITM1026 / M1042.
  • USB write control / removable-media policyM1034. Blunts the physical-access variant (Q5).
  • Real-time RMM→exfil correlation detectionM1047. Given the <1-hour speed, near-real-time alerting is essential.
Strategic — People & physical security
  • Vishing-aware user training; report-a-call SOPM1017. The decisive control for a phone-led attack.
  • Physical-security briefing on fake "IT technician" visitsM1017.
  • Data-minimization + least privilege on sensitive document storesM1057 / M1026. Shrinks what a 1-hour intrusion can take.
11

Containment Runbook

PhaseActionsOwnerEvidence
IsolateNetwork-contain the host; terminate the remote-access session; disable the involved user accountSOC L2Containment timestamp; Q1/Q2 events
TriageReconstruct the timeline (call → RMM → stage → exfil); determine exactly what data left (Q3/Q4/N4); check for USB exfilIRProcess/exfil timeline; data inventory
EradicateRemove the unsanctioned RMM; reset the user's credentials + sessions; block exfil destinationsIRRemoval log; cred reset
RecoverNotify affected parties / DPO / legal (extortion is likely); prepare for the demand; restore monitoringIR / LegalNotification record; demand log
HardenDeny unsanctioned RMM; restrict Quick Assist; help-desk verification SOP; promote Q1→Q3 correlationDetection EngControl status; detection enabled
12

Detection Coverage Map & Validation

TechniqueBehaviorCQLIOACoverage
T1566.004 / T1598Invoice lure + vishingGAP mail gw + user reporting (N1)
T1219Remote-access / RMMQ1, Q2, Q6IOA-1Good with allow-list
T1083 / T1074Search & stageQ4Partial correlate to Q1
T1567.002 / T1048Cloud / web exfilQ3IOA-2Good (+ DLP/CASB N4)
T1052.001USB exfil (physical)Q5Partial needs USB telemetry
T1657ExtortionGAP IR / legal process

Validation gates: (1) confirm process + (ideally) DLP/CASB + USB telemetry; (2) enumerate sanctioned RMM + IT host group (allow-list for Q1/Q6); (3) lab-test an unsanctioned AnyDesk run (Q1), a Quick Assist session (Q2), and a benign rclone copy (Q3); (4) promote Q1 + the Q1→Q3 real-time correlation; pair with help-desk verification training. Because of the <1-hour speed, prioritize real-time alerting.

13

Hunt Summary Ticket

TITLE:        Hunt — UNC3753 / Luna Moth / Silent Ransom Group (vishing data-theft extortion)
SEVERITY:     High (fast data theft + extortion; legitimate-tool abuse; no encryption)
SCOPE:        US legal/financial/professional-services firms; all user endpoints
HYPOTHESIS:   Invoice-themed email -> vishing call posing as IT -> screen-share / RMM install
              -> rapid search + stage -> cloud/USB exfil (often < 1 hour) -> extortion demand.
QUERIES RUN:  Q1 unsanctioned RMM (IOA) | Q2 Quick Assist | Q3 Rclone/cloud exfil (IOA) |
              Q4 search-and-stage | Q5 USB mass-copy | Q6 RMM session egress
              + Native N1-N5 (invoice lure, RMM inventory, mass file access, exfil egress, USB)
DO FIRST:     Q1 + Q3 (RMM then exfil within the hour) - REAL-TIME alert; isolate on any hit
FINDINGS:     <pending analyst execution>
GAPS:         Vishing entry is off-platform (people/process); exfil/USB need DLP/CASB telemetry
ACTIONS:      Deny unsanctioned RMM; restrict Quick Assist; help-desk verification SOP;
              egress/DLP control; promote Q1->Q3 correlation; vishing user training
OWNER:        HuntPack
VERSION:      v0.3 - 2026-06-12
14

Changelog

v0.52026-07-24CQL correctness pass. All table() calls now carry an explicit row limit: the default is 200 and truncation is silent, so a capped result was indistinguishable from a complete one. Atomic-IOC sweeps (filters over 5+ hashes or C2 IPs) use limit=max so a wide infection is never silently under-scoped; behavioural hunts use limit=200, where exceeding the cap indicates the query needs tuning. Where present, event names that do not exist in the Falcon data model were corrected (e.g. ServiceInstalled is a Sysmon concept, not a Falcon event; ElfFileWritten is ELFFileWritten) — such queries could never return a row. No detection logic, fields, or IOCs changed.
v0.42026-06-29CQL syntax review (crowdstrike-logscale-v3): removed invalid FileCreateInfo event (Q5).
v0.32026-06-12Re-hunt + reformatted to the review-v2 gold layout (fixed left-sidebar scrollspy TOC, collapsible, cloud selector inside the CQL section, per-card Copy/Open-in-Falcon, Grouped IOC Quick-Copy grid with a human-layer playbook block, coverage+validation, .ticket). Refreshed from Mandiant/FBI Flash/THN: Jan–May 2026 campaign, aliases (Luna Moth/SRG/Chatty Spider/Storm-0252), invoice→vishing→RMM/screen-share→exfil chain, <1-hour speed, 2026 physical-intrusion escalation, Conti lineage. 6 CQL + 5 native hunts, 2 IOA candidates.
v0.12026-05-26Initial pack: UNC3753 vishing extortion overview + hunts. Pre-gold top-bar layout.
15

References

TierSourceUsed For
1The Hacker News — UNC3753 vishing & physical intrusionsChain, speed, physical escalation, Conti lineage
1BleepingComputer — Silent Ransom Group fake IT callsLaw-firm targeting; vishing; RMM exfil
1FBI Flash (TLP:Clear) — Silent Ransom Group impersonating ITGov advisory; social-engineering TTPs; remediation
2Rescana — Luna Moth / SRG via RMM & social engineering · Dark Reading — escalating attacksTooling, timeline, extortion

HuntPack v0.3 · UNC3753 / Luna Moth / SRG · Generated 2026-06-12 · Defensive use only. This is a human-led, legitimate-tool-abuse attack — the durable controls are RMM governance + help-desk verification + vishing training, backed by real-time RMM→exfil correlation. Validate field names + sanctioned-RMM allow-lists in your tenant before promoting any query.