Tech Souls, Connected.

Silent Ransom Group sends imposters to offices to steal data

A ransomware group has expanded its tactics by sending people posing as IT support staff to victims’ offices, allowing them to steal data directly from computers or help other attackers gain remote access, according to Google and the FBI.

In a report published Friday, Google Threat Intelligence Group and Mandiant said the Silent Ransom Group targeted dozens of organizations between January and May, including law firms, using a mix of social engineering and physical access.

The researchers said some attacks involved attempts to obtain victims’ information “using physical, in-person access.”

Fake IT workers used in attacks

According to the FBI, members of the group have impersonated IT support personnel and visited victims’ offices.

Investigators said the imposters have:

  • Connected to employees’ computers.
  • Used USB drives to extract information.
  • Installed remote access tools.
  • Helped other attackers connect to systems remotely.

The stolen data has included:

  • Contracts.
  • Social Security numbers.
  • Financial records.
  • Tax documents.
  • Other personal information.

An FBI spokesperson confirmed the agency had seen several such cases.

“We can confirm we have seen multiple instances of individuals impersonating IT support who have gained or attempted to gain physical in-person access to victim companies’ offices and/or devices as part of Silent Ransom Group’s scheme to exfiltrate data,” the spokesperson said.

Group also relies on social engineering

The FBI issued an alert last month warning that Silent Ransom Group had been targeting law firms through phishing campaigns and social engineering.

Google said the attackers often pose as corporate IT staff and contact employees by email and phone.

Researchers said the attackers:

  • Claim to be addressing security issues.
  • Present themselves as assisting with data migration projects.
  • Build trust with victims.
  • Convince employees to join screen-sharing sessions.

The hackers then persuade victims to install screen-sharing software or exploit built-in features in platforms such as:

  • Zoom
  • Microsoft Teams

Extortion without encryption

Unlike traditional ransomware attacks, Silent Ransom Group often focuses on stealing information rather than encrypting systems.

The group operates a leak site and threatens to publish stolen data if victims refuse to pay.

“In case of ignorance or no agreement, We will notify your employees, partners and customers, after which We will publish your data,” the hackers wrote to one victim, according to Google.

Tactic has appeared before

Mandiant Chief Technology Officer Charles Carmakal said the company has encountered similar techniques in previous investigations.

“Mandiant has investigated various matters where adversaries planted insiders, bribed employees, or physically entered buildings to facilitate cyberattacks,” Carmakal said.

He added that the company has seen such methods used in other cases over the years.

TL;DR:

Google and the FBI say the Silent Ransom Group has escalated attacks by sending people posing as IT workers to victims’ offices. The imposters use USB drives and remote access tools to steal sensitive information and extort organizations.

AI summary:

  • Google and the FBI warned about attacks by Silent Ransom Group.
  • The gang has sent fake IT workers to victims’ offices.
  • Attackers use USB drives and remote access tools to steal data.
  • Law firms have been among the targets.
  • The group threatens to leak stolen information if victims refuse to pay.
Share this article
Shareable URL
Prev Post

Token bills are piling up as enterprises struggle with AI expenses

Next Post

AI coding boom pushes Supabase to $10 billion valuation

Read next