Resecurity®

1.3K posts

Resecurity® banner
Resecurity®

Resecurity®

@RESecurity

We provide technology that empowers organizations to reimagine their security & protect what matters #SaaS #RiskManagement #CyberThreatIntelligence

Los Angeles, California Katılım July 2016
1.5K Takip Edilen6.6K Takipçiler

2026 Yıllık Özeti

@RESecurity hesabının Twitter yılını gör

Mololuwa | Cybersecurity - (The God Complex)
FBI just warned that a hacking group is walking into law offices and pretending to be IT support, plugging USB drives into computers to steal data The group, known as the Silent Ransom Group (SRG), has been targeting professional services firms including law offices in the United States, with activity reported in recent years. Security researchers link parts of their infrastructure and tactics to actors previously associated with the Conti ransomware ecosystem, which broke apart after its disruption in 2022. While SRG is not a direct continuation of Conti, many analysts believe there is operational overlap in tooling and social engineering methods Unlike traditional ransomware groups that rely heavily on malware encryption, SRG operations are built around **social engineering and impersonation**. Their attacks often begin with phishing emails or phone calls where they pose as internal IT support or trusted service providers. The goal is to create urgency by inventing technical problems and convincing employees to hand over access or follow instructions A common tactic is “callback phishing,” where the victim is prompted to call a number controlled by the attackers. On the call, the attackers guide the target into installing remote access tools or granting permissions under the guise of fixing a security issue. Once access is established, they focus on locating and exfiltrating sensitive data rather than deploying destructive malware FBI reporting also notes that in some cases, if remote social engineering attempts fail, attackers may escalate to **physical approaches**, including sending individuals to a victim’s location posing as IT personnel. In these scenarios, the attacker attempts to gain direct access to a workstation and may use external storage devices to copy data. This is not the primary method of attack, but rather a lower-frequency escalation path when other methods do not succeed After data theft, SRG typically shifts to extortion. Victims receive demands threatening to leak or sell stolen information unless payment is made. In some cases, pressure tactics may include repeated contact or direct negotiation attempts The FBI has highlighted key warning signs of these intrusions, including unauthorized individuals attempting to access workstations, unexpected IT support requests, and the presence of unfamiliar external devices connected to company systems
Mololuwa | Cybersecurity - (The God Complex) tweet media
English
2
4
13
873
Yusuke Nakajima
Yusuke Nakajima@nakajimeeee·
【ソーシャルエンジニアリング・恐喝】IT部門を騙り「画面共有してください」、米国法律事務所を標的にした音声フィッシング恐喝団の全貌 MandiantとGoogle Threat Intelligence Groupは、2026年1月から5月にかけて米国の法律・金融・専門サービス業を集中的に狙う恐喝キャンペーンを実施する脅威グループ「UNC3753」(別名:Luna Moth、Silent Ransom Group)を詳細に分析した。攻撃の起点は「請求書を送った」という無害な口実メールだ。被害者が不審に思って社内ITに問い合わせようとした矢先、攻撃者が「IT担当者」を装って電話をかけ、Zoom・Teams・Quick AssistでのRMM(遠隔管理ツール)インストールへ誘導する。 侵入後の動作は驚くほど速い。iManageなどの法律文書管理システムをキーワード検索で狙い撃ちにし、W-2フォーム・SSN・秘密保持契約書・M&A関連文書を一括収集。WinSCPやRcloneで攻撃者管理のクラウドストレージへ転送するまでの全工程が1時間以内で完結したケースも確認された。データ窃取完了から30分以内に3日間の回答期限を設けた恐喝メールが届き、期限を過ぎれば従業員・取引先・クライアントへの通知とリークサイト「LEAKEDDATA」への公開を脅迫する。 さらにFBIサイバーFLASHアラートが裏付ける通り、音声フィッシングが失敗した標的に対してはIT技術者を装った人物を物理的にオフィスへ送り込み、USBストレージでのデータ直接窃取を試みるという、サイバーと物理が融合した新たなエスカレーション戦術も確認されている。 cloud.google.com/blog/topics/th…
日本語
1
0
7
1.3K
Resecurity®
Resecurity®@RESecurity·
New #ransomware projects have been identified that could be linked to the Silent Ransom Group (SRG), including Spy Corporate, which emerged in May 2026. Fast Flux provides the SRG with resilient infrastructure to extort AmLaw 100 firms. Overlap in DNS/IP - Learn More: resecurity.com/blog/article/s…
English
0
0
0
51
FalconFeeds.io
FalconFeeds.io@FalconFeedsio·
🚨 Ransomware Alert: 🇺🇸 We started monitoring a new ransomware group, "SPY CORPORATE." They had added a victim in their portal. Hahn Loeser & Parks LLP (hahnlaw.com), a USA-based law practice, has reportedly fallen victim to SPY CORPORATE Ransomware. 🔍Key Details: 🛡️Threat actor: SPY CORPORATE 📅 Reported on: 21/05/26
FalconFeeds.io tweet media
English
1
0
5
1.3K
Resecurity®
Resecurity®@RESecurity·
Fast Flux provides the SRG with resilient infrastructure to extort victims. The @FBI recently issued an advisory about this #ransomware group, which is actively targeting top AmLaw 100 firms (and other industries) through social engineering and in-person attacks. ic3.gov/CSA/2026/26052…
Resecurity® tweet media
English
0
1
3
133
Resecurity®
Resecurity®@RESecurity·
The nodes are compromised IoTs and Customer Premises Equipment (CPE) — such as routers, modems, and gateways.
English
1
1
2
113
Resecurity®
Resecurity®@RESecurity·
Resecurity is the first to uncover the SRG's Fast Flux network infrastructure and is sharing this intelligence with the #cybersecurity community to disrupt their malicious activities and enable ISP/DNS providers to counter this threat. resecurity.com/blog/article/s…
English
1
5
9
583