Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
UNC3753 Targets US Law Firms with Vishing Tactics

UNC3753 Targets US Law Firms with Vishing Tactics

Posted on June 8, 2026 By CWS

The cybercrime group UNC3753 has launched a series of intricate attacks against US law firms since early 2026. These assaults involve vishing, or voice phishing, alongside remote monitoring tools to infiltrate corporate systems and exfiltrate confidential data.

Methods and Operations of UNC3753

Operating under aliases such as Luna Moth and Silent Ransom Group, UNC3753 has been active since March 2022. Their latest series of attacks, spanning January to May 2026, targeted multiple organizations in the legal, professional, and financial sectors. The speed at which these attacks unfold is particularly concerning, with some breaches culminating in data theft within a single business day.

Unlike traditional malware-based attacks, UNC3753 employs direct engagement tactics through deceptive voice calls. This method begins with sending invoice-themed emails that lack links or attachments, designed solely to unsettle recipients and increase the likelihood of them answering subsequent fraudulent calls.

Targeting Law Firms

Law firms, often custodians of sensitive information like client files and trade secrets, are prime targets for UNC3753. The group exploits the reputational risks associated with data breaches to leverage extortion attempts. Following data theft, they swiftly initiate extortion by sending threatening emails demanding compliance within three days, under the threat of public disclosure through platforms like LEAKEDDATA.

The attackers impersonate IT support staff, using publicly available employee information to gain trust. Once engaged, they guide victims into screen-sharing sessions, facilitating the installation of remote access tools like AnyDesk and Zoho Assist.

Preventive Measures and Observations

In response to these attacks, organizations are advised to implement rigorous verification processes for IT communications, restrict remote access tool installations, and ensure multi-factor authentication on sensitive document repositories. Data exfiltration typically involves tools like WinSCP and Rclone, and UNC3753 has been known to physically infiltrate offices, posing as technicians to extract data directly.

Firms should monitor network traffic for anomalies and configure alerts for unusual download patterns. Blocking phishing domains at the DNS level and enforcing visitor verification protocols are also crucial in mitigating these risks.

Conclusion and Future Implications

The ongoing threat from UNC3753 highlights the importance of robust cyber defenses and vigilant monitoring. As this group refines its techniques, law firms and related sectors must remain proactive in enhancing their security measures to protect against such sophisticated attacks.

Cyber Security News Tags:corporate security, cyber attacks, Cybersecurity, data exfiltration, data protection, law firms, ransom threats, remote monitoring, UNC3753, Vishing

Post navigation

Previous Post: Lansing College Data Breach Affects 174,000 Individuals
Next Post: The Emerging Threat of Mythos in Open Source

Related Posts

Microsoft Enhances Security to Block Copilot in Office Files Microsoft Enhances Security to Block Copilot in Office Files Cyber Security News
Critical Fortinet Vulnerability Exploited, CISA Issues Warning Critical Fortinet Vulnerability Exploited, CISA Issues Warning Cyber Security News
Lyrie.ai Introduces AI Agent Security Protocol Lyrie.ai Introduces AI Agent Security Protocol Cyber Security News
APT36 Hackers Used Python-Based ELF Malware to Target Indian Government Entities APT36 Hackers Used Python-Based ELF Malware to Target Indian Government Entities Cyber Security News
Microsoft Halts Key Open-Source Project Developer Accounts Microsoft Halts Key Open-Source Project Developer Accounts Cyber Security News
New SHUYAL Attacking 19 Popular Browsers to Steal Login Credentials New SHUYAL Attacking 19 Popular Browsers to Steal Login Credentials Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Certighost Flaw in AD CS Allows Domain Compromise
  • Tego AI Reveals Second Security Issue in Claude Software
  • SourTrade Malvertising Evades Detection with Unique Malware
  • Microsoft Ends Unwanted Ads in Windows 11
  • Golden Chickens Unveils New Malware Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Certighost Flaw in AD CS Allows Domain Compromise
  • Tego AI Reveals Second Security Issue in Claude Software
  • SourTrade Malvertising Evades Detection with Unique Malware
  • Microsoft Ends Unwanted Ads in Windows 11
  • Golden Chickens Unveils New Malware Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark