incident-responsetrade-pressNewsThe Broadside2 min read

Leaked chats show Russia-based extortion gang directing "agents" into US law firms

An FBI flash alert earlier this year said the group was posing as IT personnel to gain physical access to victim computers, and one firm's negotiation transcript in the leak says an individual entered its New York office and copied files.


TL;DR

A leaked chat archive reviewed by Recorded Future News shows members of Silent Ransom Group (a Russia-based data-extortion operation linked to the defunct Conti syndicate) directing operatives inside the United States whom they call "agents." The archive spans August 2025 to September 2026. One negotiation transcript in the cache records a law firm stating it knew an individual had entered its New York office and copied files onto a flash drive. The FBI issued a public advisory earlier this year warning that Silent Ransom Group members were physically visiting victim offices under the guise of IT support. Chainalysis tied cryptocurrency addresses in the leak to known SRG extortions, but the firm said it could not confirm the totality of claims in the archive.

The FBI's advisory earlier this year landed as unusual even by the standards of ransomware warnings: a cyber extortion group, it said, was sending people to physically visit US law firms and gain access to computers. A newly surfaced chat archive offers a window into how that tactic was discussed and directed from inside the group itself.

The cache, posted to an .onion site in early October by an unidentified source, contains thousands of messages from August 2025 to September 2026. Members of Silent Ransom Group (also tracked as Luna Moth, Chatty Spider, and UNC3753) track dozens of victims, negotiate ransom payments, and manage a roster of US-based operatives called "agents."

Parts of the archive have been corroborated independently. Chainalysis examined cryptocurrency addresses in the leak and tied them to known SRG extortions, though it cautioned it could not confirm the full scope of claims. The FBI's earlier flash alert independently documents the same physical-access tactic the chat members discuss at length.

One negotiation transcript in the leak captures a law firm telling the extortionists it knew an individual had entered its New York office and copied files onto a flash drive. The firm said its executives had authorized $1 million to settle the demand but wanted proof that every copy of the data would be destroyed, citing evidence that LockBit had failed to delete victim data after payment. The $1 million figure and the firm's corroboration of the physical entry give the chat logs more weight than mere brainstorming.

What the recruitment looks like

The group advertised for operatives through paid Telegram posts disguised as job listings (nightclub promotion, courier work, security) targeting Russian speakers. A roster tracks agents by code number and city. One entry describes a 17-year-old as ready to work. The chats show the leader estimating in February that only a fraction of applicants were usable.

The operational brainstorming is extensive. Members discussed buying delivery uniforms for cover, commissioning lawyer-face masks, and purchasing smart glasses to record office interiors. An earlier shopping list included a $3,200 UV-capable printer and holographic materials, equipment consistent with producing fake IDs. Funds were sent to forgers, including one in New York.

Nothing in the archive confirms that the pizza-delivery ruse or mask schemes were actually deployed. The negotiation transcript from the New York firm, though, shows that someone did walk into an office and walk out with data. The broader tactic matches what the FBI described, and the chat logs show it wasn't improvised, it was workshopped, funded, and staffed.


Published ·Deep Fathom

Leaked chats show Russia-based extortion gang directing "agents" into US law firms — The Broadside