Cnn Russian Silent Ransom Group Uses In-Person Tactics to Target US Law Firms
Article Content
- •Silent Ransom Group hires individuals to physically insert USB malware into law firm computers.
- •The group has extorted approximately $100 million from law firms in the last six months.
- •FBI investigations indicate a growing trend of physical infiltration tactics in cybercrime.
The Silent Ransom Group has been implicated in a series of cyberattacks targeting US law firms, employing operatives to physically access computers and insert USB devices. This tactic aims to bypass remote security measures and enhance ransom negotiations by obtaining sensitive client data. In April, a lawyer at a New Jersey law firm received a call from an alleged IT support member, leading to an in-person visit that raised suspicions. The group reportedly offers $500 for such visits, which have occurred in major cities like New York and Washington, D.C. The FBI has estimated that the group has extorted around $100 million from law firms in the past six months. This method of attack is risky, leaving behind evidence such as surveillance footage. The group has also utilized distractions, such as posing as delivery personnel, to facilitate their operations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Conti in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Permanent Data Loss from Iranian Drone Strikes on AWS in Middle East Amazon Web Services (AWS) reported that multiple Iranian drone strikes have caused permanent data loss in its cloud infrastructure located in Bahrain and the UAE. The strikes, which began in March 2026, targeted AWS data centers in retaliation for US and Israeli military actions against Iran. AWS confirmed that it…