Cybercrime
UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign
Cyber RTJune 8, 20263 min read

Between January and May 2026, a financially motivated extortion campaign targeted U.S. organizations in professional, legal, and financial services. Attributed to threat actor UNC3753, also known as Chatty Spider, the group used voice phishing and social engineering to gain remote access. They exfiltrated sensitive data, including legal agreements and financial records, and issued extortion demands, threatening to publish stolen information if not paid.
Between January and May 2026, a financially motivated data theft extortion campaign targeted numerous organizations in the U.S., specifically within professional, legal, and financial services. This campaign has been attributed to a threat actor known as UNC3753, also referred to as Chatty Spider, Luna Moth, and Silent Ransom Group (SRG). The group is known for using sophisticated techniques such as voice phishing (vishing) and social engineering to infiltrate corporate environments.
UNC3753 employs deceptive tactics, such as posing as IT support, to initiate phone conversations with targets. They use pretexts like data migration or invoice-related issues to convince victims to host screen-sharing sessions and download remote monitoring and management (RMM) utilities. Once they gain access, the threat actors either directly search for and exfiltrate files or manipulate victims into performing these actions on their behalf, targeting sensitive information like proprietary legal agreements, personally identifiable information (PII), and financial records.
In some cases, the attackers have physically accessed victims' systems by impersonating IT technicians to enter corporate offices. This method involves using removable USB media to steal data, marking an escalation in UNC3753's capabilities as noted by the FBI. The physical intrusion tactic highlights the lengths to which the group will go to exfiltrate valuable data.
UNC3753 shares tactical similarities with another threat cluster, UNC2686, known for BazarCall-style campaigns in 2021. Although the group has previously deployed LockBit Black ransomware, since 2022, they have focused on extortion-only operations, threatening to publish stolen data on the LEAKEDDATA site if victims do not comply with their demands. Both UNC3753 and UNC2686 are believed to be offshoots of the defunct Conti ransomware gang.
Since March 2025, UNC3753 has impersonated corporate IT help desks to trick victims into joining screen-sharing sessions on platforms like Zoom and Microsoft Teams, bypassing traditional security controls. They initiate campaigns with benign, invoice-themed emails that raise security concerns, making targets more susceptible to follow-up voice calls. These emails lack active links or malicious attachments, serving primarily to establish a pretext for further engagement.
Once a session is established, attackers guide victims to install legitimate remote desktop software, using services like "privnote[.]com" to share installation instructions. This software allows them to access corporate virtual desktop infrastructure (VDI) and delve deeper into corporate file systems, targeting sensitive data such as tax filings, audits, and Social Security numbers. The captured data is then exfiltrated using tools like WinSCP or Rclone.
The final stage involves sending an extortion demand via email, typically within 30 minutes of exiting the target environment. Victims are given a three-day deadline to negotiate, with threats to notify employees and clients of the breach or publish the stolen data if they remain unresponsive. Legal services firms are particularly high-value targets due to their repositories of sensitive client information and the reputational risks they face, making them more likely to comply with extortion demands.
Overall, the campaign underscores the effectiveness of targeting the human element through social engineering, enabling threat actors to bypass robust technical defenses. Legal entities, in particular, are vulnerable due to their sensitive data and the potential for reputational damage, making them prime targets for extortion. The article encourages readers to follow updates on platforms like Google News, Twitter, and LinkedIn for more exclusive content on cybersecurity threats.


