Russian Extortion Gang Recruited 'Agents' to Infiltrate US Law Firms
Leaked chats reveal a Russian-based extortion group, linked to Silent Ransom Group, plotted to send operatives into US law firms to steal data and extort victims.

A sophisticated Russian cybercriminal organization, identified by blockchain analysis as the Silent Ransom Group (also known as Luna Moth and Chatty Spider), has been revealed to be actively plotting to infiltrate U.S. law firms by sending operatives, referred to as "agents," directly into their offices. Leaked chat logs, spanning from August 2025 to September 2026 and posted anonymously online, detail thousands of messages where group members discuss tracking dozens of victims, negotiating multi-million dollar ransom payments, and directing these "agents" operating within the United States. Some of the targeted organizations have not publicly disclosed any security incidents.
The leaked archive contains a mix of apparent extortion records, brainstorming sessions, and even violent fantasies, making it challenging to verify the execution of every scheme. However, independent analysis by Chainalysis has corroborated parts of the leak, linking cryptocurrency addresses within the archive to known extortions by the Silent Ransom Group. The FBI has also flagged the group's unusual tactic of using "agents" for physical infiltration, noting in a prior alert that members posed as IT personnel to gain access to victim computer systems.
Discussions within the chats reveal a months-long planning process for getting "agents" into law firm offices. Tactics considered included operatives posing as delivery personnel, such as pizza delivery drivers, to bypass reception and then claiming to be IT support. Other proposals involved creating custom masks to impersonate lawyers or using smart glasses to record office interiors while posing as clients. The group also discussed purchasing specialized equipment like printers with ultraviolet capabilities and materials for producing fake identification cards, with expenses noted for individuals creating forged documents.
The recruitment of these "agents" appears to have been conducted through paid advertisements on Telegram, disguised as ordinary job listings for roles like nightclub promotion or courier work, primarily targeting Russian speakers. The process was reportedly messy, with a roster detailing agents by code and city, including an underage recruit. The group's leadership expressed contempt for the recruits, viewing them as disposable and discussing methods to track them to prevent theft or betrayal. The "conversion" rate, where recruits proved usable, was estimated by the group's leader to be as low as one in ten.
Victim management followed a structure akin to a sales pipeline, with negotiations progressing through stages like "chat," "offer," "contract," and finally "gold." The archive records approximately $200 million in claimed settlements across dozens of firms marked as "gold," though these figures are the group's own and could not be independently verified. The group also discussed highly coercive tactics, including following senior lawyers and executives, learning their routines, and even photographing the children of targets as leverage. Other extreme proposals included fake escort websites, sexual blackmail schemes, and kidnapping.
While the full extent of these elaborate infiltration schemes remains unverified, the FBI's confirmation of the physical access tactic aligns with the leaked communications. The group's willingness to employ such direct, physical methods, combined with sophisticated digital extortion, highlights a concerning evolution in their operational capabilities and a significant threat to sensitive organizations like law firms that handle confidential client data.
The revelations underscore the growing threat posed by sophisticated cybercriminal groups that blend traditional hacking with physical infiltration and exploitation tactics. The targeting of law firms, in particular, suggests an intent to access highly sensitive information for maximum leverage in ransom negotiations, potentially impacting corporate clients and ongoing legal cases.