Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cybercriminals Exploit Screen-Sharing to Steal Legal Data

Cybercriminals Exploit Screen-Sharing to Steal Legal Data

Posted on June 17, 2026 By CWS

A cybercriminal syndicate has been targeting law firms and professional service providers in the U.S. since early 2026. This group employs deception to gain unauthorized access to sensitive data, manipulating victims into unwittingly granting them system access.

Identified as UNC3753, the group also goes by aliases like “Luna Moth” and “Silent Ransom Group.” They have been active since March 2022, continuously adapting their strategies to maintain efficacy. Google Cloud’s Threat Intelligence Group highlighted that their attacks often conclude within a business day, with data theft sometimes occurring in less than an hour.

Deceptive Tactics and Quick Execution

The group initiates their attacks with a seemingly harmless invoice email, devoid of malicious content, designed to make recipients susceptible to follow-up calls. Posing as IT helpdesk personnel, the attackers persuade targets to engage in screen-sharing sessions and install remote monitoring tools.

Once access is secured, attackers search for valuable files such as legal agreements and financial records, which they then transfer to their own cloud storage. Following this data theft, victims receive extortion emails threatening public disclosure unless demands are met swiftly.

Exploitation of Remote Management Tools

During the attack, victims are often instructed to use tools like Zoom or Teams for screen sharing, followed by installing software like AnyDesk for continued access. Attackers use self-destructing message services to conceal their tracks, sending commands and download links discreetly.

In documented instances, attackers have exfiltrated vast amounts of data, such as 1.7 gigabytes from a OneDrive account, and in some cases, even more from virtual desktops. The stolen information is threatened with publication on sites like LEAKEDDATA if ransom demands are not met.

Physical Intrusions Enhance the Threat

Beyond digital breaches, UNC3753 has engaged in physical intrusions. Posing as IT technicians, they have accessed corporate offices to extract data using USB drives. This escalation is concerning for companies relying on basic security measures.

Google’s Threat Intelligence Group advises firms to enforce rigorous access policies, including photo ID checks, and to train employees on recognizing such tactics. Digital safeguards should include blocking unauthorized remote tools and setting up alerts for unusual data access patterns.

Maintaining vigilance and updating security protocols are crucial in preventing data breaches of this nature. Organizations are encouraged to stay informed through trusted sources and regularly review their cybersecurity measures.

Cyber Security News Tags:cyber attacks, cyber threats, Cybersecurity, data breach, data exfiltration, Extortion, Google Cloud, law firms, legal data theft, physical intrusion, remote access, RMM tools, screen-sharing, threat intelligence, UNC3753

Post navigation

Previous Post: Ghostwriter Hackers Target Gmail with Phishing Emails
Next Post: Hackers Exploit AI Tools for Advanced Cyber Attacks

Related Posts

Destructive Akira Ransomware Attack with a Single Click on CAPTCHA in Malicious Website Destructive Akira Ransomware Attack with a Single Click on CAPTCHA in Malicious Website Cyber Security News
Hackers Exploit Meta Business Manager for Phishing Hackers Exploit Meta Business Manager for Phishing Cyber Security News
One Identity Upgrades Identity Manager for Stronger Security One Identity Upgrades Identity Manager for Stronger Security Cyber Security News
CISA Warns of Fortinet FortiWeb OS Command Injection Vulnerability Exploited in the Wild CISA Warns of Fortinet FortiWeb OS Command Injection Vulnerability Exploited in the Wild Cyber Security News
Critical Zero-Day in Cisco Products Exploited in Attacks Critical Zero-Day in Cisco Products Exploited in Attacks Cyber Security News
Hackers Launched 8.1 Million Attack Sessions to React2Shell Vulnerability Hackers Launched 8.1 Million Attack Sessions to React2Shell Vulnerability Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Adform’s Ad Platform Breached to Distribute Crypto Malware
  • Brinks Home Confirms Major Data Breach Amid Hacker Claims
  • Flaw in Coldcard Wallet Triggers $70 Million Bitcoin Heist
  • Top Web Application Firewalls for 2026: Expert Ranking
  • Top DNS Security Solutions for 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Adform’s Ad Platform Breached to Distribute Crypto Malware
  • Brinks Home Confirms Major Data Breach Amid Hacker Claims
  • Flaw in Coldcard Wallet Triggers $70 Million Bitcoin Heist
  • Top Web Application Firewalls for 2026: Expert Ranking
  • Top DNS Security Solutions for 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark