Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Silent Ransom Group Employs Fast Flux for Stealth Attacks

Silent Ransom Group Employs Fast Flux for Stealth Attacks

Posted on June 8, 2026 By CWS

The Silent Ransom Group (SRG), a notorious ransomware entity, has been leveraging a fast flux network to obscure its operational infrastructure, according to warnings from cybersecurity firm Resecurity. This method involves using a network of infected devices to hide their servers’ locations.

SRG’s Tactics and Targeted Industries

Known by aliases such as Chatty Spider, Luna Moth, and UNC3753, the group employs voice phishing and social engineering techniques. They send phishing emails disguised as data migration notices or invoices, luring recipients into phone interactions with impostors posing as IT experts. These interactions often lead to victims unknowingly facilitating remote access to their systems.

SRG’s primary targets include U.S. law firms, where they have been reported to send operatives in person to insert USB drives for data exfiltration or malware installation. The group has also targeted finance, healthcare, insurance, and hospitality sectors due to the sensitive data these industries handle.

Operational Strategy and Fast Flux Networks

After penetrating an organization’s defenses, SRG typically seeks lateral movement and data exfiltration rather than deploying file-encrypting malware. Within a short span post-exfiltration, usually around 30 minutes, the group sends extortion emails threatening to release the stolen data publicly if demands are not met. They intensify their pressure tactics by reaching out to the victim’s employees and partners if initial threats are ignored.

Resecurity’s recent findings highlight SRG’s use of a fast flux network comprising infected routers, modems, and other IoT devices spread across 18 countries, including regions in Latin America, Eastern Europe, and Asia. This technique involves changing DNS records rapidly, making it difficult to pinpoint server locations.

Impact and Continued Threat

SRG’s activities have significantly impacted the legal sector, with law firms representing nearly a quarter of all ransomware incidents reported in early 2026, as noted by Resecurity. Their focus on data theft and extortion has contributed to an increase in such incidents.

A Google report indicates that SRG has been active since at least 2022, with overlapping activities with other groups like UNC2686, known for BazarCall campaigns. The group’s continued evolution and adoption of sophisticated techniques such as fast flux underline the persistent threat they pose globally.

As SRG continues its assault across various industries, vigilance and updated cybersecurity measures remain crucial for organizations to protect themselves against such advanced threats.

Security Week News Tags:cyber attacks, Cybersecurity, data exfiltration, DNS, fast flux, global threat, IoT devices, law firms, Phishing, Ransomware, Resecurity, Silent Ransom Group

Post navigation

Previous Post: VerdantBamboo Targets Linux with New BRICKSTORM Variant
Next Post: OWASP Unveils AI Security Report for Enhanced Protection

Related Posts

Data Breach at Healthcare Services Firm Episource Impacts 5.4 Million People Data Breach at Healthcare Services Firm Episource Impacts 5.4 Million People Security Week News
China’s Cyber Silence is More Worrying Than Russia’s Noise, Chief Cybersecurity Strategist Says China’s Cyber Silence is More Worrying Than Russia’s Noise, Chief Cybersecurity Strategist Says Security Week News
Stragglers From Myanmar Scam Center Raided by Army Cross Into Thailand as Buildings are Blown Up Stragglers From Myanmar Scam Center Raided by Army Cross Into Thailand as Buildings are Blown Up Security Week News
AI Tools Vulnerable to Comment-Based Prompt Injection AI Tools Vulnerable to Comment-Based Prompt Injection Security Week News
ICS Patch Tuesday: Fixes Announced by Siemens, Schneider, Rockwell, ABB, Phoenix Contact ICS Patch Tuesday: Fixes Announced by Siemens, Schneider, Rockwell, ABB, Phoenix Contact Security Week News
Account Takeover Fraud Caused 2 Million in Losses in 2025: FBI Account Takeover Fraud Caused $262 Million in Losses in 2025: FBI Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Security Concerns Rise with AI-Driven Vibe Coding
  • The Emerging Threat of Mythos in Open Source
  • UNC3753 Targets US Law Firms with Vishing Tactics
  • Lansing College Data Breach Affects 174,000 Individuals
  • Critical Check Point VPN Vulnerability Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Security Concerns Rise with AI-Driven Vibe Coding
  • The Emerging Threat of Mythos in Open Source
  • UNC3753 Targets US Law Firms with Vishing Tactics
  • Lansing College Data Breach Affects 174,000 Individuals
  • Critical Check Point VPN Vulnerability Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark