Skip to content
Silent Ransom Group hires US visitors to plug USB malware into law firm computers

Silent Ransom Group hires US visitors to plug USB malware into law firm computers

Mezha June 27, 2026

Operatives posing as IT staff visited major firms in person to insert USB devices. The pattern suggests an organized effort to bypass remote defenses and strengthen ransom demands.

In April, one of the leading American law firms faced an incident: a virus that spread within the network caused damage and demanded an urgent response. At first it seemed the problem could be solved remotely, but it later became clear: physical access to the computer of a specific employee was required.

According to incident response specialists, the applicant claimed that he was from IT support and needed physical access because remote fixes were not working. The attorney asked the visitor to come to his desk at the firm’s New Jersey office.

The day, the receptionist reported that a visitor from IT had arrived at the firm.

Then the alarm bells rang: why does an IT worker need to appear at reception?

According to Leeann Nicolo, who is responsible for incident response at the cyber-insurance company Coalition, which engaged the firm for investigation, the visitor fled the building when the attorney approached the reception. This is one of the cases supporting suspicions that the Russian-speaking Silent Ransom Group hires people in the United States for in-person presence and connection of USB drives to firm computers in order to bypass remote security systems.

According to CNN, the group promises $500 for visiting firms and connecting USB drives. Such actions are viewed as part of a powerful tactic, where physical access complements cyberattacks.

People involved in such actions are called “cannon fodder” for the criminals – expendable assets in a larger cybercrime war. This tactic is rare and risky, as it leaves traces, including video surveillance that the FBI can analyze.

According to one law enforcement officer who tracks the group, the criminals are increasingly bold whom they recruit online to perform tasks.

The aim of these operations is to strengthen the criminals’ position during ransom negotiations by obtaining sensitive client data. If firms do not pay, the criminals may disclose the stolen information.

Cybersecurity experts estimate that Silent Ransom Group has already raised $100 million from firms in the last six months. Other sources put the amount in tens of millions of dollars.

When remote access does not provide enough data, the group raises the stakes with Outsourcing burglary: hired workers visit major U.S. cities, including New York and Washington, DC.

In one case, a man posing as IT support entered another American law firm and spoke Russian in smart glasses – likely to give the group live access to the computers in the building. Before the intruder reached the lawyer’s desk, another group member called a mobile number, disguising himself as a FedEx courier, to distract him. The intruder connected a USB drive, but the firm’s security blocked the attack.

I expect that they are targeting every leading US law firm.

The FBI notes that Silent Ransom Group is the only known “data-extortion” group that physically visits the property of its victims. According to the agency, there have been numerous attempts at physical access in various cities across the United States.

Other cybercriminals previously used threats, or swatting, but many government and private-sector experts are not yet ready for a coordinated response to both cyber and physical threats.

According to Genevieve Stark of Google Threat Intelligence Group, many threat actors are increasingly bold in recruiting people to act online; the physical aspect may be a threat we do not expect. This could be a trend where individuals are more likely to trust those who appear in person because it is unexpected.

Hackers of Silent Ransom Group are not strangers to the FBI: it is known that some of its members were linked to Conti – a well-known group that disbanded in 2022 after a leak of chats by a Ukrainian citizen in response to Russia’s full-scale aggression against Ukraine. The FBI had for years gathered evidence on Conti and tracked the movements of its members; one person allegedly involved in the group previously pleaded guilty in the United States. Now the FBI is building a case against Silent Ransom Group, tracking firms’ payments through blockchain, CNN sources say.

The investigation is not entirely digital: in the past year, at least two American law firms received letters demanding ransom in cryptocurrency or money to not disclose data. The senders were labeled as different groups, but Nicolo believes this could be a “false flag”; cyber experts believe that Silent Ransom Group is also involved in such malicious actions.

“I think we will see more of these incidents,” says Nicolo, noting that the situation requires attention from law enforcement and corporate structures.

Coordinated, stone-age–style attacks with the addition of physical access heighten the risks for the largest US law firms. The high price of this malicious tactic is not only the compromise of client data but also potential consequences for firms’ reputations and client trust. Analysts emphasize the need to bolster internal security procedures, check visitors, and strengthen monitoring of access to critical systems. In the future, expect greater attention from law enforcement and corporations to a coordinated response to both cyber and physical threats.

Don’t miss other news:

Extracted Entities