# UNC3753's Dangerous Escalation: From Phishing Calls to Physical Intrusions in U.S. Data Theft Campaign
A financially motivated threat actor known as UNC3753 (also tracked as Chatty Spider, Luna Moth, and Silent Ransom Group) has escalated its extortion tactics from voice phishing to in-person office intrusions, according to a joint investigation by Google Mandiant and Google Threat Intelligence Group. The campaign has targeted dozens of U.S. organizations across professional services, law firms, and financial institutions between January and May 2026, combining sophisticated social engineering with on-site theft operations.
## The Threat
Google's research team, led by analysts Chad Reams, Tufail Ahmed, Keith Knapp, Ashley Frazer, and Tyler McLellan, has documented a multi-faceted extortion operation targeting high-value sectors where sensitive data commands premium prices. The threat actors combine traditional vishing (voice phishing) techniques with a novel escalation: physical intrusions into corporate facilities, where attackers pose as IT technicians to directly steal data using removable media.
The campaign represents an evolution in tactics that moves beyond screen-based social engineering. Rather than relying solely on convincing targets to download remote access software, UNC3753 actors now physically enter buildings, insert USB drives into corporate systems, and exfiltrate data while on-site—a tactic that largely bypasses traditional endpoint and network security controls.
### Targeted Industries and Data
- Proprietary legal agreements and contracts
- Personally identifiable information (PII)
- Financial records and sensitive business documents
## Background and Context
UNC3753 is assessed to be an offshoot of the now-defunct Conti ransomware gang, one of the most destructive cybercriminal organizations of the past five years. Following international sanctions and law enforcement pressure on Conti, its network fragmented into smaller, specialized groups—a pattern seen repeatedly in the ransomware ecosystem.
### Evolution of the Threat Actor
| Timeline | Activity | Notable Characteristics |
|----------|----------|------------------------|
| 2021 | BazarCall campaigns | Subscription cancellation lures, callback phishing |
| 2021-2022 | LockBit Black deployment | Ransomware-based extortion operations |
| 2022-present | Extortion-only focus | Shift away from encryption, emphasis on data theft |
| March 2025 onward | Screen-sharing abuse | Impersonation of internal IT staff on Zoom/Teams |
| Early 2026 | Physical intrusions | In-person office visits for direct data theft |
Related threat cluster: UNC2686 shares tactical overlaps with UNC3753, suggesting shared infrastructure, training, or operational leadership. Both groups employ similar social engineering methodologies and have been linked to the broader Conti ecosystem.
## Tactics and Techniques
### Phase 1: Initial Compromise via Vishing
The attack chain begins with benign-appearing emails, often invoice-themed, sent from actor-controlled consumer email addresses. These initial messages contain no malicious links or attachments—their sole purpose is establishing pretext.
1. Email pretext: Generic invoice-themed lure raises security concerns internally
2. Follow-up call: Actor impersonates IT support or help desk staff
3. Pretexts used:
- Data migration initiatives
- Invoice verification or payment issues
- System updates or security patches
### Phase 2: Remote Access Installation
Once the actor establishes phone contact, they convince the target to initiate screen-sharing:
- AnyDesk (legitimate remote desktop software)
- Bomgar (now Cobalt)
- SuperOps RMM
- Zoho Assist
Distribution method: Installation instructions are shared via privnote[.]com, a self-destructing notes service that removes evidence after the target reads the message.
### Phase 3: Physical Intrusion (New Escalation)
The most concerning development is the integration of physical intrusion:
## Technical Details
### Attack Infrastructure
UNC3753 leverages both legitimate services and commodity tools to minimize forensic footprints:
### Victim Profiling and Selection
Researchers note that UNC3753 appears to conduct preliminary reconnaissance before campaigns. The group targets organizations with:
## Implications for Organizations
### Immediate Risks
1. Physical security gaps: Organizations must now integrate physical access controls with cybersecurity protocols. A contractor walking in with a USB drive is as dangerous as a compromised network connection.
2. Supply chain vulnerability: Law firms, financial services, and professional services firms are critical information nodes in their respective industries—compromise of one firm can expose dozens of clients.
3. Social engineering sophistication: UNC3753's ability to impersonate internal IT staff suggests either insider knowledge or sophisticated reconnaissance. This represents escalation beyond script-reading vishing.
4. Ransomware-free extortion model: The shift from encryption-based ransomware to data theft only makes attribution harder and victims more likely to comply (no systems are down, operations continue, attackers simply threaten publication).
### Who Is at Greatest Risk
## Recommendations
### For Security Teams
### For C-Suite and Business Leaders
### For Law Firms and Financial Services
---
## HackWire Analysis
The evolution of UNC3753 from vishing calls to physical office intrusions marks a significant inflection point in cybercriminal tactics. What matters now is not just *what* attackers can compromise remotely—it's that they've weaponized physical access to bypass defenses that presume threat vectors are primarily digital.
This represents a pattern we've seen before with organized crime syndicates pivoting to new specializations after law enforcement pressure. When Conti fragmented, its constituent groups didn't disappear; they decentralized and specialized. UNC3753 has chosen an asymmetric path: rather than competing with sophisticated APT groups in stealth and persistence, they've leaned into social engineering's most reliable vector—human psychology—and paired it with physical execution. A USB drive in a human hand defeats most security architectures designed to stop malware propagation through network boundaries.
The geographic and sectoral focus is also telling. Law firms and financial services firms aren't targeted because they're "strategic" in the nation-state sense—they're targeted because they are information aggregators. A single compromised law firm handling M&A transactions exfiltrates data on multiple Fortune 500 companies. A financial advisor's client list becomes an intelligence asset for other crimes. The extortion model (publish data or pay) aligns with market forces: these sectors have clients who will pressure them to pay quietly to avoid disclosure.
For defenders, the implication is urgent: you cannot secure systems that are physically accessible to social-engineered attackers. This isn't a criticism of endpoint detection tools—it's a recognition that USB exfiltration is faster than any network-based detection. Organizations in high-risk sectors need to treat physical access to network-connected systems as seriously as they treat zero-day vulnerabilities. The badge at the lobby is now part of the security perimeter, not a separate domain.
— HackWire Editorial
---
## Related Coverage