Silent Ransom Group Targets Law Firms with Fast Flux Infrastructure

Silent Ransom Group Targets Law Firms with Fast Flux Infrastructure

First seen 7 Jun 2026, 14:49 UTC Securityaffairs.Cowww.resecurity.com 80% similarity 69.5

Article Content

Browse articles
ThreatCluster

The Silent Ransom Group (SRG), a cyber extortion group active since 2022, has been identified using DNS Fast Flux infrastructure to target U.S. law firms and other sensitive industries. Unlike traditional ransomware, SRG focuses on data theft and extortion without encryption. The FBI has issued warnings about ongoing attacks, particularly against law firms that manage sensitive client data. Resecurity has uncovered SRG's Fast Flux network, which uses compromised devices to create a resilient infrastructure against takedowns. The group is known for exploiting vulnerabilities in IoT devices and customer premises equipment. The advisory highlights the need for collaboration between public and private sectors to combat this threat. The SRG's activities have been linked to other underground projects, indicating a broader network of cybercrime. Law firms are particularly vulnerable due to the sensitive nature of the data they handle.

Key Points: • The Silent Ransom Group uses DNS Fast Flux to evade detection and maintain operations. • Law firms are primary targets due to their management of sensitive client data. • The FBI has issued advisories regarding ongoing attacks against U.S. businesses.

ThreatCluster AI

Timeline

2022-01-01
SRG begins operations
The Silent Ransom Group is identified as active in cyber extortion, focusing on data theft.
Securityaffairs.Co
2026-05-01
FBI issues advisory
The FBI warns of ongoing attacks by SRG targeting U.S. law firms and businesses.
Securityaffairs.Co
2026-06-07
Resecurity uncovers Fast Flux network
Resecurity identifies SRG's Fast Flux infrastructure, sharing intelligence to disrupt their activities.
Resecurity

Community

Browse all →