# Silent Ransom Group Deploys Global Fast Flux Botnet to Hide Ransomware Infrastructure


The Silent Ransom Group—a sophisticated ransomware operation targeting high-value organizations across multiple sectors—has escalated its technical capabilities by leveraging a sophisticated DNS Fast Flux network spanning 18 countries and 22 internet service providers, according to new threat intelligence from Resecurity. The botnet, which rotates compromised routers, modems, and IoT devices to mask command-and-control servers, represents a significant evolution in how the group conceals its infrastructure while conducting high-impact extortion campaigns.


## The Threat: Advanced Social Engineering Meets Technical Sophistication


The Silent Ransom Group (SRG), also tracked by security researchers as Chatty Spider, Luna Moth, and UNC3753, has become one of the most prolific and dangerous ransomware operations targeting U.S. organizations. What distinguishes SRG from many competing ransomware groups is its hybrid approach: combining cutting-edge technical tradecraft with low-tech but highly effective social engineering.


The group's attack methodology begins with carefully crafted phishing emails, typically themed around data migration services or invoice requests. When recipients engage with these messages, they're drawn into phone conversations with SRG operatives who pose as IT specialists. Through a combination of social pressure, technical impersonation, and persuasion, these operators convince victims to initiate screen-sharing sessions and install remote access software—granting the attackers direct entry into corporate networks.


SRG's sophistication extends beyond digital channels. The FBI has documented the group conducting physical intrusions, with operatives hand-delivering USB drives to targeted organizations for direct data exfiltration or malware deployment. This willingness to combine virtual and physical attack vectors demonstrates the group's commitment to achieving its objectives and reflects the extremely high-value nature of their targets.


## Background and Context: A Ransomware Gang with Multiple Identities


SRG has been active since at least 2022, establishing itself as a persistent threat to organizations holding valuable data. The group operates across multiple industries, with particular focus on:


  • Law Firms (primary target—24% of all Q1 2026 ransomware incidents in this sector)
  • Financial Services
  • Healthcare Organizations
  • Insurance Companies
  • Hospitality Sector

  • The group's selection of targets is strategic. Organizations in these sectors typically maintain extensive databases of sensitive information—client communications, financial records, patient data, or proprietary business information—making them prime candidates for extortion-based attacks. Unlike traditional ransomware groups that encrypt files to force payment, SRG operates under a different model: data theft and extortion.


    Google's threat intelligence team has identified operational overlap between SRG and UNC2686, a financially motivated threat actor known for BazarCall campaigns and historical use of TrickBot, Ursnif, and BazarLoader malware. This overlap suggests potential shared infrastructure, common operatives, or coordinated campaigns among related threat groups.


    ## Technical Details: DNS Fast Flux and Global Botnet Infrastructure


    The newly disclosed fast flux network represents a significant technical advancement for SRG's operations. DNS Fast Flux is a technique that allows threat actors to hide the true location of their command-and-control (C&C) servers by rapidly rotating DNS records. Instead of pointing a domain to a single server, the technique involves:


  • Rapid IP rotation: DNS records are changed frequently (sometimes multiple times per minute)
  • Multiple name servers: The group cycles through numerous compromised DNS servers
  • Legitimate domains: The technique often hijacks or leverages legitimate domain infrastructure
  • Botnet reliance: Requires control over thousands of infected devices to function effectively

  • To operate a fast flux network of this scale, threat actors must first compromise a large number of internet-connected devices. Resecurity's analysis identified that SRG has compromised:


    | Device Type | Count | Primary Function |

    |---|---|---|

    | Routers | Hundreds | Network access point compromise |

    | Modems | Hundreds | ISP-level access control |

    | Gateways | Multiple | Traffic redirection |

    | IoT/CPE Devices | Large botnet | Distributed DNS rotation |


    Geographic Distribution: The botnet spans 18 countries across multiple regions:

  • Latin America: Multiple compromised nodes providing Western Hemisphere access
  • Eastern Europe: Core infrastructure region with heavy ISP representation
  • Central Asia: Growing regional presence
  • Middle East: Strategic positioning
  • Africa: Expanding footprint
  • East Asia: Asian-Pacific presence
  • Caribbean: Additional Western Hemisphere coverage

  • This geographic distribution serves multiple strategic purposes: it complicates attribution, enables redundancy, bypasses regional blocking measures, and provides multiple points for DNS query resolution.


    Identified Domains: Resecurity confirmed that the fast flux network has rotated DNS records for:

  • ep6pheij[.]com
  • business-data-leaks[.]com

  • These domains serve as the infrastructure backbone for SRG's command-and-control communications and data leak site operations.


    ## Attack Timeline and Extortion Model


    SRG operates on a remarkably efficient timeline once network access is achieved:


    Phase 1 (Initial Access → Exfiltration): Days to weeks of lateral movement, data discovery, and careful exfiltration of sensitive files


    Phase 2 (Immediate Pressure): Within 30 minutes of data exfiltration, SRG sends initial extortion emails to victim organizations, threatening to publish stolen data on its clear web data leak site


    Phase 3 (Escalation): If victims don't respond to initial demands, the group contacts employees and business partners directly, increasing pressure through multiple communication channels


    This compressed timeline leaves organizations minimal time to respond, coordinate with law enforcement, or engage in negotiation before data is publicly released.


    ## Implications: Industry Impact and Systemic Risk


    The impact of SRG's campaigns has been substantial, particularly for the legal industry. According to Resecurity's analysis, law firms accounted for almost one-quarter of all ransomware-related incidents tracked in Q1 2026, making the sector the fourth-most targeted industry overall. The uptick directly correlates with SRG's strategic focus on legal organizations.


    For law firms specifically, the implications are severe:

  • Client confidentiality breaches: Legal privileged communications exposed
  • Regulatory penalties: GLBA violations, state bar discipline, federal oversight
  • Reputational damage: Client trust erosion in a relationship-based industry
  • Competitive intelligence theft: Opposing counsels' strategies exposed

  • However, SRG's targeting extends far beyond law firms. Healthcare organizations face HIPAA violations and patient data exposure. Financial services companies risk regulatory action and customer data compromise. Insurance companies become targets for claims information, policyholder data, and underwriting details.


    The use of sophisticated fast flux infrastructure suggests SRG is investing heavily in operational security and long-term sustainability. This is not a fly-by-night criminal operation; this is organized crime with sophisticated technical infrastructure.


    ---


    ## HackWire Analysis


    The DNS Fast Flux disclosure marks an important inflection point in how mature ransomware groups defend their criminal infrastructure. For years, researchers could track ransomware operations by identifying C&C server IP addresses and domains. SRG's adoption of fast flux networks—a technique popularized during the Zeus botnet era over a decade ago—demonstrates that established criminal organizations are recycling proven evasion tactics and modernizing them with current botnet capabilities.


    What's particularly concerning is the geographic distribution. A botnet spanning 18 countries across five continents suggests SRG either has significant operational capacity to compromise devices globally, or is purchasing/renting fast flux services from underground criminal markets. Either scenario indicates a well-resourced threat actor with sophisticated supply chains.


    The targeting pattern also reveals an understudied vulnerability: professional services firms. Law firms, accounting practices, and consulting companies maintain extraordinary concentrations of sensitive data but often lag in security maturity compared to regulated industries like finance or healthcare. SRG has clearly identified this gap and is exploiting it systematically. The fact that law firms comprised 24% of ransomware incidents in Q1 2026 suggests the group is outpacing general ransomware trends and capturing disproportionate market share in their vertical.


    For defenders, the lesson is clear: vishing and social engineering remain the most reliable entry vector. No amount of infrastructure security prevents an employee from voluntarily installing remote access software during a convincing phone call. Organizations must invest in security awareness training that specifically addresses voice-based social engineering—a tactic that still catches even security-conscious employees.


    Finally, the 30-minute window between exfiltration and extortion is noteworthy. This suggests either SRG is automating their notification process, or they maintain near-real-time alerting when data leaves target networks. Either way, organizations have minimal time to detect the breach independently before pressure arrives. Incident response plans must assume attackers will contact you before you discover them.


    — HackWire Editorial


    ---


    ## Recommendations for Organizations


    For Law Firms and Professional Services:

  • Implement strict controls on remote access software; prohibit personal installations
  • Deploy advanced voice-based phishing detection
  • Conduct regular vishing simulations to train staff
  • Assume the 30-minute timeline and establish immediate escalation procedures for suspected breaches

  • For All Organizations:

  • Monitor DNS resolution patterns for anomalous name server changes
  • Block known SRG domains (ep6pheij[.]com, business-data-leaks[.]com) at all network boundaries
  • Implement data loss prevention (DLP) controls that trigger alerts on bulk exfiltration attempts
  • Assume breach notifications will come from threat actors before internal detection
  • Coordinate with law enforcement (FBI Cyber Division) and sector ISACs for threat intelligence sharing

  • For Service Providers and ISPs:

  • Monitor for fast flux patterns within your customer base
  • Implement controls that detect rapid DNS record changes
  • Collaborate with Resecurity and other threat intelligence firms on botnet mitigation

  • ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)