Find notable cyber news and cases, enriched with sources, timelines, and signals.

Silent Ransom Group shifts from Conti-linked ransomware participation to standalone data-theft extortion

Threat Actor Meta
First reported
Last updated
Happening score
H score 21
2 unique sources, 2 articles

Summary

Hide ▲

Silent Ransom Group (UNC3753) is a standalone data-theft extortion actor that has operated separately since 2022 after the Conti shutdown, using stolen data and leak threats rather than ransomware encryption. Recent reporting shows the group still fits that extortion model through vishing, social engineering, and tool-assisted access, reinforcing its role as a focused extortion brand tied to the broader Conti lineage.

Related Happenings

Vect and TeamPCP industrialize ransomware through a supply-chain credential-theft alliance

Threat Actor Meta
H score67 First: 03.07.2026 14:30 Last: 03.07.2026 14:30 Sources 1

About this happening: Vect and TeamPCP formed a new ransomware-as-a-service partnership that combines supply-chain credential theft with extortion, expanding the risk of follow-on attac...

DragonForce / Hackledorb pivots from RaaS to a formalized cartel structure

Threat Actor Meta
H score26 First: 18.06.2026 16:30 Last: 18.06.2026 16:30 Sources 1

About this happening: Hackledorb has pivoted DragonForce from a conventional ransomware-as-a-service (RaaS) model into a formalized cartel structure, signaling a more organized and dura...

Silent Ransom Group US law firm IT impersonation campaign

Campaign
H score36 First: 29.05.2026 16:00 Last: 29.05.2026 16:00 Sources 1

How related: The activity has been attributed by Google Mandiant and Google Threat Intelligence Group (GTIG) to a threat actor dubbed UNC3753, which is also known as Chatty Spider, Luna Moth, and Silent Ransom Group (SRG).

About this happening: Silent Ransom Group (SRG), also tracked as UNC3753, Chatty Spider, and Luna Moth, is running a financially motivated data theft extortion campaign against do...

U.S. sentencing of Deniss Zolotarjovs in Karakurt ransomware case

Law Enforcement
H score39 First: 05.05.2026 13:13 Last: 05.05.2026 13:13 Sources 1

About this happening: Deniss Zolotarjovs was sentenced to 8.5 years in prison in the United States for serving as a Karakurt ransomware negotiator, resolving a cross-border cybercrime c...

Beast ransomware group’s RaaS model and shared TTPs exposed through an open server

Threat Actor Meta
H score37 First: 20.03.2026 18:31 Last: 20.03.2026 18:31 Sources 1

About this happening: An exposed Beast ransomware group server now shows its RaaS operating model and reusable toolset, complicating attribution across ransomware crews. The recovered materials...

Timeline

  1. 07.06.2026 17:09 3 articles · 1mo ago

    Initial report: Silent Ransom Group shifts from Conti-linked ransomware participation to standalone data-theft extortion

    Initial Disclosure

    The actor separated from the Conti syndicate after its 2022 shutdown and reoriented around standalone data-theft extortion. That transition established Silent Ransom Group as a distinct extortion brand rather than a ransomware-encryption operation.

    Show sources