# UNC3753's Dangerous Escalation: From Phishing Calls to Physical Intrusions in U.S. Data Theft Campaign


A financially motivated threat actor known as UNC3753 (also tracked as Chatty Spider, Luna Moth, and Silent Ransom Group) has escalated its extortion tactics from voice phishing to in-person office intrusions, according to a joint investigation by Google Mandiant and Google Threat Intelligence Group. The campaign has targeted dozens of U.S. organizations across professional services, law firms, and financial institutions between January and May 2026, combining sophisticated social engineering with on-site theft operations.


## The Threat


Google's research team, led by analysts Chad Reams, Tufail Ahmed, Keith Knapp, Ashley Frazer, and Tyler McLellan, has documented a multi-faceted extortion operation targeting high-value sectors where sensitive data commands premium prices. The threat actors combine traditional vishing (voice phishing) techniques with a novel escalation: physical intrusions into corporate facilities, where attackers pose as IT technicians to directly steal data using removable media.


The campaign represents an evolution in tactics that moves beyond screen-based social engineering. Rather than relying solely on convincing targets to download remote access software, UNC3753 actors now physically enter buildings, insert USB drives into corporate systems, and exfiltrate data while on-site—a tactic that largely bypasses traditional endpoint and network security controls.


### Targeted Industries and Data

  • Primary targets: Legal firms, financial services, professional services companies
  • Data of interest:
  • - Proprietary legal agreements and contracts

    - Personally identifiable information (PII)

    - Financial records and sensitive business documents

  • Exfiltration method: External hard drives and USB drives inserted directly by attackers
  • Monetization: Extortion demands with threatened publication on LEAKEDDATA leak site

  • ## Background and Context


    UNC3753 is assessed to be an offshoot of the now-defunct Conti ransomware gang, one of the most destructive cybercriminal organizations of the past five years. Following international sanctions and law enforcement pressure on Conti, its network fragmented into smaller, specialized groups—a pattern seen repeatedly in the ransomware ecosystem.


    ### Evolution of the Threat Actor


    | Timeline | Activity | Notable Characteristics |

    |----------|----------|------------------------|

    | 2021 | BazarCall campaigns | Subscription cancellation lures, callback phishing |

    | 2021-2022 | LockBit Black deployment | Ransomware-based extortion operations |

    | 2022-present | Extortion-only focus | Shift away from encryption, emphasis on data theft |

    | March 2025 onward | Screen-sharing abuse | Impersonation of internal IT staff on Zoom/Teams |

    | Early 2026 | Physical intrusions | In-person office visits for direct data theft |


    Related threat cluster: UNC2686 shares tactical overlaps with UNC3753, suggesting shared infrastructure, training, or operational leadership. Both groups employ similar social engineering methodologies and have been linked to the broader Conti ecosystem.


    ## Tactics and Techniques


    ### Phase 1: Initial Compromise via Vishing


    The attack chain begins with benign-appearing emails, often invoice-themed, sent from actor-controlled consumer email addresses. These initial messages contain no malicious links or attachments—their sole purpose is establishing pretext.


    1. Email pretext: Generic invoice-themed lure raises security concerns internally

    2. Follow-up call: Actor impersonates IT support or help desk staff

    3. Pretexts used:

    - Data migration initiatives

    - Invoice verification or payment issues

    - System updates or security patches


    ### Phase 2: Remote Access Installation


    Once the actor establishes phone contact, they convince the target to initiate screen-sharing:


  • Platforms exploited: Zoom, Microsoft Teams, Windows Quick Assist
  • RMM tools deployed:
  • - AnyDesk (legitimate remote desktop software)

    - Bomgar (now Cobalt)

    - SuperOps RMM

    - Zoho Assist


    Distribution method: Installation instructions are shared via privnote[.]com, a self-destructing notes service that removes evidence after the target reads the message.


    ### Phase 3: Physical Intrusion (New Escalation)


    The most concerning development is the integration of physical intrusion:


  • Attacker impersonates IT technician, facilities contractor, or system administrator
  • Access method: Walks into corporate office, often during business hours
  • Data theft: Uses USB drive or external hard drive to extract files directly from connected systems
  • Bypass: Bypasses perimeter security, network-based detection, and many endpoint controls
  • Dwell time: Minimal—extract and exfiltrate within minutes

  • ## Technical Details


    ### Attack Infrastructure


    UNC3753 leverages both legitimate services and commodity tools to minimize forensic footprints:


  • Command and control: Minimal use of dedicated infrastructure; reliance on legitimate platforms (Zoom, Teams)
  • File distribution: privnote[.]com (self-destructing notes) for sharing RMM installation instructions
  • Data exfiltration: External drives and USB media transported by physical actors
  • Leak site: LEAKEDDATA, where threatened data is published if extortion demands aren't met

  • ### Victim Profiling and Selection


    Researchers note that UNC3753 appears to conduct preliminary reconnaissance before campaigns. The group targets organizations with:


  • High-value confidential documents (law firms, financial services)
  • Known security gaps or limited internal security awareness
  • Dispersed office environments with multiple sites
  • Complex organizational structures facilitating social engineering

  • ## Implications for Organizations


    ### Immediate Risks


    1. Physical security gaps: Organizations must now integrate physical access controls with cybersecurity protocols. A contractor walking in with a USB drive is as dangerous as a compromised network connection.


    2. Supply chain vulnerability: Law firms, financial services, and professional services firms are critical information nodes in their respective industries—compromise of one firm can expose dozens of clients.


    3. Social engineering sophistication: UNC3753's ability to impersonate internal IT staff suggests either insider knowledge or sophisticated reconnaissance. This represents escalation beyond script-reading vishing.


    4. Ransomware-free extortion model: The shift from encryption-based ransomware to data theft only makes attribution harder and victims more likely to comply (no systems are down, operations continue, attackers simply threaten publication).


    ### Who Is at Greatest Risk


  • Law firms (handling mergers, intellectual property, client confidential information)
  • Financial advisory and accounting firms (tax information, financial records, client lists)
  • Professional services (consulting strategies, client relationships, competitive intelligence)
  • Mid-market companies (fewer security resources than enterprises, higher-value targets than small businesses)

  • ## Recommendations


    ### For Security Teams


  • Integrate physical and logical security: Coordinate badge access systems with network monitoring. Unknown IT contractor on-site? Cross-reference against actual scheduled maintenance.
  • Prohibit USB connections: Disable or restrict USB ports on systems containing sensitive data. Use hardware-based enforcement, not policy alone.
  • Mandatory caller verification: Before IT support initiates screen-sharing, verify through independent phone numbers listed in directory systems.
  • Train on vishing indicators: Multi-phase attacks succeed when initial pretext emails succeed. Security awareness must include recognizing generic invoice lures.

  • ### For C-Suite and Business Leaders


  • Audit physical access controls: Who can walk into your building and access computer areas? Update access policies quarterly.
  • Conduct tabletop exercises: Simulate a vishing attack followed by physical intrusion. Test incident response procedures.
  • Increase cyber insurance scrutiny: Verify coverage includes data extortion (not just ransomware) and physical intrusion scenarios.

  • ### For Law Firms and Financial Services


  • Segregate client data: Isolate highly sensitive client information on air-gapped systems or restricted networks.
  • Implement air-gapped backups: Ensure critical files exist on systems that cannot be directly accessed or exfiltrated via USB.
  • Client notification protocol: Establish clear procedures for notifying clients if their data is exposed, including timeline and communication channels.

  • ---


    ## HackWire Analysis


    The evolution of UNC3753 from vishing calls to physical office intrusions marks a significant inflection point in cybercriminal tactics. What matters now is not just *what* attackers can compromise remotely—it's that they've weaponized physical access to bypass defenses that presume threat vectors are primarily digital.


    This represents a pattern we've seen before with organized crime syndicates pivoting to new specializations after law enforcement pressure. When Conti fragmented, its constituent groups didn't disappear; they decentralized and specialized. UNC3753 has chosen an asymmetric path: rather than competing with sophisticated APT groups in stealth and persistence, they've leaned into social engineering's most reliable vector—human psychology—and paired it with physical execution. A USB drive in a human hand defeats most security architectures designed to stop malware propagation through network boundaries.


    The geographic and sectoral focus is also telling. Law firms and financial services firms aren't targeted because they're "strategic" in the nation-state sense—they're targeted because they are information aggregators. A single compromised law firm handling M&A transactions exfiltrates data on multiple Fortune 500 companies. A financial advisor's client list becomes an intelligence asset for other crimes. The extortion model (publish data or pay) aligns with market forces: these sectors have clients who will pressure them to pay quietly to avoid disclosure.


    For defenders, the implication is urgent: you cannot secure systems that are physically accessible to social-engineered attackers. This isn't a criticism of endpoint detection tools—it's a recognition that USB exfiltration is faster than any network-based detection. Organizations in high-risk sectors need to treat physical access to network-connected systems as seriously as they treat zero-day vulnerabilities. The badge at the lobby is now part of the security perimeter, not a separate domain.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Social Engineering](https://www.hackwire.news/category/social-engineering) and [Extortion](https://www.hackwire.news/category/extortion)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)