VYPR
ransomwarePublished Jul 30, 2026· 1 source

Ransomware Group Silent Ransom Employs Physical Infiltration Tactics Amidst Declining Payouts

The FBI has identified the ransomware group Silent Ransom, also known as Luna Moth, as employing increasingly audacious tactics, including physical infiltration of victim premises, to secure payments despite a general decline in ransomware victim payouts.

Ransomware actors are increasingly resorting to extreme measures to maintain profitability as fewer victims are willing to pay ransoms, and those who do pay smaller amounts. The FBI has highlighted the Silent Ransom group's success in bucking this trend by employing sophisticated social engineering tactics that include physical infiltration of target organizations. This group, also tracked under aliases such as Luna Moth, Chatty Spider, and UNC3753, has a documented history of leveraging social engineering to gain access.

Silent Ransom's most concerning tactic involves posing as IT personnel to gain physical access to victim locations, primarily high-profile U.S. law firms. Once inside, they infiltrate networks under the guise of performing routine computer maintenance. This physical presence allows them to directly exfiltrate sensitive data, which they then use as leverage for substantial ransom demands. According to ransomware response firm Coveware, this strategy has proven particularly lucrative, with the threat of public exposure of legally sensitive records compelling victims to pay large sums.

While physical infiltration is a notable escalation, it is not the group's primary method. The FBI notes that Silent Ransom typically initiates attacks through mass emails or direct phone calls, attempting to trick targets into installing remote access tools or divulging credentials. Only when these remote social engineering attempts fail do they resort to sending an operative on-site. In these physical intrusions, the attacker might claim to need to "image the device or create a backup file" to address a perceived issue, thereby gaining direct access to systems.

The FBI's alert, issued earlier this month, specifically warned about the group's escalation to on-site visits. Although Silent Ransom's affiliates have targeted various sectors including insurance, finance, and healthcare, the group has shown a consistent focus on U.S.-based law firms since the spring of 2023. This targeted approach, combined with their aggressive tactics, has allowed them to achieve significant financial gains.

This group's success stands in stark contrast to the broader ransomware landscape. Overall, the ransomware business model is showing signs of deflation. Coveware's research indicates a significant drop in victim payouts, with the percentage of victims paying ransoms falling from 23% to 19% between the first and second quarters of 2026, an all-time low. Payments for data theft alone also saw a sharp decline, from 29% to 15%.

Despite the overall decrease in ransom payments, the median ransom amount dropped by 50% to $150,000 in the second quarter. However, the average ransom paid surged dramatically by 176% to $1.9 million. This surge is largely attributed to Silent Ransom's high-value targeting of major law firms, demonstrating that while fewer organizations are paying, the successful ones are paying substantially more.

To combat these sophisticated attacks, the FBI urges organizations to implement stringent visitor credential validation policies, including making copies of identification. They also recommend developing clear communication and authentication protocols for IT support. The bureau is actively seeking surveillance footage from affected firms to aid in identifying and apprehending the perpetrators behind these physical infiltration schemes.

The FBI's call for better information sharing among policymakers, law enforcement, industry leaders, and victims is crucial. As Coveware's lead director of incident response for the U.K. and EMEA, Magnus Jelen, stated, "Paying criminals for a promise no one can audit or enforce is not the way forward. Hope is not a strategy." The continued success of groups like Silent Ransom underscores the need for robust security measures and proactive defense strategies.

Synthesized by Vypr AI