Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cybercriminals Exploit Screen-Sharing to Steal Legal Data

Cybercriminals Exploit Screen-Sharing to Steal Legal Data

Posted on June 17, 2026 By CWS

A cybercriminal syndicate has been targeting law firms and professional service providers in the U.S. since early 2026. This group employs deception to gain unauthorized access to sensitive data, manipulating victims into unwittingly granting them system access.

Identified as UNC3753, the group also goes by aliases like “Luna Moth” and “Silent Ransom Group.” They have been active since March 2022, continuously adapting their strategies to maintain efficacy. Google Cloud’s Threat Intelligence Group highlighted that their attacks often conclude within a business day, with data theft sometimes occurring in less than an hour.

Deceptive Tactics and Quick Execution

The group initiates their attacks with a seemingly harmless invoice email, devoid of malicious content, designed to make recipients susceptible to follow-up calls. Posing as IT helpdesk personnel, the attackers persuade targets to engage in screen-sharing sessions and install remote monitoring tools.

Once access is secured, attackers search for valuable files such as legal agreements and financial records, which they then transfer to their own cloud storage. Following this data theft, victims receive extortion emails threatening public disclosure unless demands are met swiftly.

Exploitation of Remote Management Tools

During the attack, victims are often instructed to use tools like Zoom or Teams for screen sharing, followed by installing software like AnyDesk for continued access. Attackers use self-destructing message services to conceal their tracks, sending commands and download links discreetly.

In documented instances, attackers have exfiltrated vast amounts of data, such as 1.7 gigabytes from a OneDrive account, and in some cases, even more from virtual desktops. The stolen information is threatened with publication on sites like LEAKEDDATA if ransom demands are not met.

Physical Intrusions Enhance the Threat

Beyond digital breaches, UNC3753 has engaged in physical intrusions. Posing as IT technicians, they have accessed corporate offices to extract data using USB drives. This escalation is concerning for companies relying on basic security measures.

Google’s Threat Intelligence Group advises firms to enforce rigorous access policies, including photo ID checks, and to train employees on recognizing such tactics. Digital safeguards should include blocking unauthorized remote tools and setting up alerts for unusual data access patterns.

Maintaining vigilance and updating security protocols are crucial in preventing data breaches of this nature. Organizations are encouraged to stay informed through trusted sources and regularly review their cybersecurity measures.

Cyber Security News Tags:cyber attacks, cyber threats, Cybersecurity, data breach, data exfiltration, Extortion, Google Cloud, law firms, legal data theft, physical intrusion, remote access, RMM tools, screen-sharing, threat intelligence, UNC3753

Post navigation

Previous Post: Ghostwriter Hackers Target Gmail with Phishing Emails

Related Posts

WordPress Plugin Vulnerability Let Attackers Bypass Authentication via Social Login WordPress Plugin Vulnerability Let Attackers Bypass Authentication via Social Login Cyber Security News
Hackers Hijacking Snap Domains to Posion Linux Software Packages for Desktops and Servers Hackers Hijacking Snap Domains to Posion Linux Software Packages for Desktops and Servers Cyber Security News
Malicious VS Code Extensions Attacking Windows Solidity Developers to Steal Login Credentials Malicious VS Code Extensions Attacking Windows Solidity Developers to Steal Login Credentials Cyber Security News
MacSync macOS Infostealer Leverage ClickFix-style Attack to Trick Users Pasting a Single Terminal Command MacSync macOS Infostealer Leverage ClickFix-style Attack to Trick Users Pasting a Single Terminal Command Cyber Security News
Self-Propagating GlassWorm Weaponizing VS Code Extensions to Attack macOS Users Self-Propagating GlassWorm Weaponizing VS Code Extensions to Attack macOS Users Cyber Security News
Microsoft Enhances Windows Security by Turning Off File Previews for Downloads Microsoft Enhances Windows Security by Turning Off File Previews for Downloads Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cybercriminals Exploit Screen-Sharing to Steal Legal Data
  • Ghostwriter Hackers Target Gmail with Phishing Emails
  • Cyberattack Uses Fake CAPTCHA to Deploy Malware
  • OnionDrop Campaign Delivers LegionLoader via gainmsg C2
  • GitGuardian Enhances Developer Security with New Endpoint Protection

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cybercriminals Exploit Screen-Sharing to Steal Legal Data
  • Ghostwriter Hackers Target Gmail with Phishing Emails
  • Cyberattack Uses Fake CAPTCHA to Deploy Malware
  • OnionDrop Campaign Delivers LegionLoader via gainmsg C2
  • GitGuardian Enhances Developer Security with New Endpoint Protection

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark