Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
UNC3753 Targets US Law Firms with Vishing Tactics

UNC3753 Targets US Law Firms with Vishing Tactics

Posted on June 8, 2026 By CWS

The cybercrime group UNC3753 has launched a series of intricate attacks against US law firms since early 2026. These assaults involve vishing, or voice phishing, alongside remote monitoring tools to infiltrate corporate systems and exfiltrate confidential data.

Methods and Operations of UNC3753

Operating under aliases such as Luna Moth and Silent Ransom Group, UNC3753 has been active since March 2022. Their latest series of attacks, spanning January to May 2026, targeted multiple organizations in the legal, professional, and financial sectors. The speed at which these attacks unfold is particularly concerning, with some breaches culminating in data theft within a single business day.

Unlike traditional malware-based attacks, UNC3753 employs direct engagement tactics through deceptive voice calls. This method begins with sending invoice-themed emails that lack links or attachments, designed solely to unsettle recipients and increase the likelihood of them answering subsequent fraudulent calls.

Targeting Law Firms

Law firms, often custodians of sensitive information like client files and trade secrets, are prime targets for UNC3753. The group exploits the reputational risks associated with data breaches to leverage extortion attempts. Following data theft, they swiftly initiate extortion by sending threatening emails demanding compliance within three days, under the threat of public disclosure through platforms like LEAKEDDATA.

The attackers impersonate IT support staff, using publicly available employee information to gain trust. Once engaged, they guide victims into screen-sharing sessions, facilitating the installation of remote access tools like AnyDesk and Zoho Assist.

Preventive Measures and Observations

In response to these attacks, organizations are advised to implement rigorous verification processes for IT communications, restrict remote access tool installations, and ensure multi-factor authentication on sensitive document repositories. Data exfiltration typically involves tools like WinSCP and Rclone, and UNC3753 has been known to physically infiltrate offices, posing as technicians to extract data directly.

Firms should monitor network traffic for anomalies and configure alerts for unusual download patterns. Blocking phishing domains at the DNS level and enforcing visitor verification protocols are also crucial in mitigating these risks.

Conclusion and Future Implications

The ongoing threat from UNC3753 highlights the importance of robust cyber defenses and vigilant monitoring. As this group refines its techniques, law firms and related sectors must remain proactive in enhancing their security measures to protect against such sophisticated attacks.

Cyber Security News Tags:corporate security, cyber attacks, Cybersecurity, data exfiltration, data protection, law firms, ransom threats, remote monitoring, UNC3753, Vishing

Post navigation

Previous Post: Lansing College Data Breach Affects 174,000 Individuals
Next Post: The Emerging Threat of Mythos in Open Source

Related Posts

Darknet Market Archetyp Dismantled by Authorities in Joint Action ‘Operation Deep Sentinel’ Darknet Market Archetyp Dismantled by Authorities in Joint Action ‘Operation Deep Sentinel’ Cyber Security News
15+ Weaponized npm Packages Attacking Windows Systems to Deliver Vidar Malware 15+ Weaponized npm Packages Attacking Windows Systems to Deliver Vidar Malware Cyber Security News
Beware of Weaponized Google Meet page that uses ClickFix to deliver Malicious Payload Beware of Weaponized Google Meet page that uses ClickFix to deliver Malicious Payload Cyber Security News
OpenAI Unveils GPT-5.6 with Unlimited Chat Access OpenAI Unveils GPT-5.6 with Unlimited Chat Access Cyber Security News
Lumma Stealer Uses Browser Fingerprinting to Collect Data and for Stealthy C&C Server Communications Lumma Stealer Uses Browser Fingerprinting to Collect Data and for Stealthy C&C Server Communications Cyber Security News
Hackers Can Attack Active Directory Sites to Escalate Privileges and Compromise the Domain Hackers Can Attack Active Directory Sites to Escalate Privileges and Compromise the Domain Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Innovative InjectEave Attack Eavesdrops on Headphones from 30 Meters
  • OpenAI Pledges $1 Billion for AI Cybersecurity Tools
  • New Linux Malware Tengu Hides as Kernel Process
  • ConnectWise Highlights ScreenConnect Security Issue
  • Microsoft Phasing Out Manifest V2 Extensions by 2027

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Innovative InjectEave Attack Eavesdrops on Headphones from 30 Meters
  • OpenAI Pledges $1 Billion for AI Cybersecurity Tools
  • New Linux Malware Tengu Hides as Kernel Process
  • ConnectWise Highlights ScreenConnect Security Issue
  • Microsoft Phasing Out Manifest V2 Extensions by 2027

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark