Silent Ransom Group shifts from Conti-linked ransomware participation to standalone data-theft extortion
Threat Actor Meta
Summary
Hide ▲
Show ▼
Silent Ransom Group (UNC3753) is a standalone data-theft extortion actor that has operated separately since 2022 after the Conti shutdown, using stolen data and leak threats rather than ransomware encryption. Recent reporting shows the group still fits that extortion model through vishing, social engineering, and tool-assisted access, reinforcing its role as a focused extortion brand tied to the broader Conti lineage.
Related Happenings
Vect and TeamPCP industrialize ransomware through a supply-chain credential-theft alliance
Threat Actor Meta
H score67
First: 03.07.2026 14:30
Last: 03.07.2026 14:30
Sources 1
About this happening:
Vect and TeamPCP formed a new ransomware-as-a-service partnership that combines supply-chain credential theft with extortion, expanding the risk of follow-on attac...
Vect and TeamPCP industrialize ransomware through a supply-chain credential-theft alliance
Threat Actor MetaAbout this happening: Vect and TeamPCP formed a new ransomware-as-a-service partnership that combines supply-chain credential theft with extortion, expanding the risk of follow-on attac...
DragonForce / Hackledorb pivots from RaaS to a formalized cartel structure
Threat Actor Meta
H score26
First: 18.06.2026 16:30
Last: 18.06.2026 16:30
Sources 1
About this happening:
Hackledorb has pivoted DragonForce from a conventional ransomware-as-a-service (RaaS) model into a formalized cartel structure, signaling a more organized and dura...
DragonForce / Hackledorb pivots from RaaS to a formalized cartel structure
Threat Actor MetaAbout this happening: Hackledorb has pivoted DragonForce from a conventional ransomware-as-a-service (RaaS) model into a formalized cartel structure, signaling a more organized and dura...
Silent Ransom Group US law firm IT impersonation campaign
Campaign
H score36
First: 29.05.2026 16:00
Last: 29.05.2026 16:00
Sources 1
How related:
The activity has been attributed by Google Mandiant and Google Threat Intelligence Group (GTIG) to a threat actor dubbed UNC3753, which is also known as Chatty Spider, Luna Moth, and Silent Ransom Group (SRG).
About this happening:
Silent Ransom Group (SRG), also tracked as UNC3753, Chatty Spider, and Luna Moth, is running a financially motivated data theft extortion campaign against do...
Silent Ransom Group US law firm IT impersonation campaign
CampaignHow related: The activity has been attributed by Google Mandiant and Google Threat Intelligence Group (GTIG) to a threat actor dubbed UNC3753, which is also known as Chatty Spider, Luna Moth, and Silent Ransom Group (SRG).
About this happening: Silent Ransom Group (SRG), also tracked as UNC3753, Chatty Spider, and Luna Moth, is running a financially motivated data theft extortion campaign against do...
U.S. sentencing of Deniss Zolotarjovs in Karakurt ransomware case
Law Enforcement
H score39
First: 05.05.2026 13:13
Last: 05.05.2026 13:13
Sources 1
About this happening:
Deniss Zolotarjovs was sentenced to 8.5 years in prison in the United States for serving as a Karakurt ransomware negotiator, resolving a cross-border cybercrime c...
U.S. sentencing of Deniss Zolotarjovs in Karakurt ransomware case
Law EnforcementAbout this happening: Deniss Zolotarjovs was sentenced to 8.5 years in prison in the United States for serving as a Karakurt ransomware negotiator, resolving a cross-border cybercrime c...
Beast ransomware group’s RaaS model and shared TTPs exposed through an open server
Threat Actor Meta
H score37
First: 20.03.2026 18:31
Last: 20.03.2026 18:31
Sources 1
About this happening:
An exposed Beast ransomware group server now shows its RaaS operating model and reusable toolset, complicating attribution across ransomware crews. The recovered materials...
Beast ransomware group’s RaaS model and shared TTPs exposed through an open server
Threat Actor MetaAbout this happening: An exposed Beast ransomware group server now shows its RaaS operating model and reusable toolset, complicating attribution across ransomware crews. The recovered materials...
Timeline
-
07.06.2026 17:09 3 articles · 1mo ago
Initial report: Silent Ransom Group shifts from Conti-linked ransomware participation to standalone data-theft extortion
Initial DisclosureThe actor separated from the Conti syndicate after its 2022 shutdown and reoriented around standalone data-theft extortion. That transition established Silent Ransom Group as a distinct extortion brand rather than a ransomware-encryption operation.
Show sources
- Silent Ransom Group targets law firms with fake IT support calls — www.bleepingcomputer.com — 07.06.2026 17:09
- Silent Ransom Group targets law firms with fake IT support calls — www.bleepingcomputer.com — 07.06.2026 17:09
- UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign — thehackernews.com — 08.06.2026 10:39