Article 78Y17 Money trail backs leaked chats from extortion crew that walks into US law firms

Money trail backs leaked chats from extortion crew that walks into US law firms

by
from www.theregister.com - Articles on (#78Y17)
Story ImageCryptocurrency transactions lend credibility to parts of a purported leak from Russian extortion crew Silent Ransom Group (SRG), according to blockchain researchers. Chainalysis said some wallet addresses in the material match its existing intelligence, although it could not authenticate the entire collection. It posted: "While we cannot speak to the totality of claims documented in the leak, we can confirm that certain leaked SRG addresses sit downstream of millions of dollars in ransomware payments that SRG has extorted from victims." Despite its name, SRG is known for stealing data and demanding payment rather than deploying ransomware. Its methods include callback phishing and physical intrusions. The FBI warned in May that people posing as IT support staff were entering law offices and copying files onto USB drives. Chainalysis said the transaction histories of two SRG wallet addresses detailed hundreds of thousands of dollars' worth of funds sent from the wallet of a known SRG member. The company believes the funds it observed flowing through the leaked addresses came from a large extortion payment made by a victim in mid-2026, and were used to pay for SRG's expenses, such as members' wages and IT infrastructure. "Our confidence stems from the leaked addresses' transaction history," said Chainalysis. "Several payment addresses contained within the leaks source their funds from confirmed SRG ransom payments. "For example, one of the Silent members' wallets specified in the leaked chats is funded entirely from a $10 million+ victim payment that SRG collected in mid-2026, and which we were tracking before the leak." Blockchain analytics company Crystal Intelligence separately examined the leaked chats and traced payments to wallets identified in them. The chats claim SRG received about $207 million from 27 firms between April and September 2026. Crystal could not verify that total, although it traced funds to an upstream collection wallet that received about 2,675 Bitcoin over its lifetime. Crystal identified a range of ways SRG spent this money. Sometimes the funds would be sent directly to affiliates, but the group had ways of swapping the crypto for cash they could actually use. According to Crystal's analysis, the group used instant exchangers, services that swap crypto for cash sent to Russian bank cards, and for larger deposits, a Moscow-based broker named "Zhenya" who provided the group with physical cash in exchange for crypto. The leaked chats suggest members suspected Zhenya of skimming money through the exchange rate, Crystal said. Crystal said the chats identified a Bitcoin-to-Zelle service advertised on Telegram as SAFU Exchange. Its database associates the same handle with a Georgia-based exchange it describes as unlicensed and sanctions-flagged. The riskiest of its payment methods was reserved for smaller sums paid directly to the likes of "field agents and document forgers," who received their payments directly into their exchange wallets. Crystal said these were regulated exchanges that verify customers' identities. "This is the network's weakest point, and the most direct route for law enforcement to identify the people behind the handles," it said. According to Crystal, the chats included advice to buy property in person and discussions of purchasing new-build homes and sports cars. They said to use mortgages for the homes and, if any banks asked questions about the source of the money, to tell them it was an inheritance or a gift, or to produce a fake loan agreement. The material appeared online this week under the title "The Luna Moth Files," a reference to another name researchers use for SRG. SRG has been active since around 2022 and has maintained a consistent focus on law firms, although it has branched out to other types of organizations too. The group's usual method is callback phishing. Presenting as IT support staff, they convince marks to return their calls and grant remote access to their desktop sessions, running various tools to steal data. The Luna Moth Files website claims the material contains nearly 5,700 internal messages identifying senior members and field agents. Those identities have not been independently verified. These "field agents" are the individuals who were recruited to walk into US law offices to steal data via a thumb drive. Crystal's analysis of the chat logs concluded that these "field agents" were recruited on Russian-language job boards. Job listings promised $300+ per night for "nightclub promoters," although respondents were instead pushed into the physical intrusion line of work. The FBI's May advisory renewed its warning about SRG following fresh reports of attacks that spring. It did not disclose how many incidents involved physical intrusions. (R)
External Content
Source RSS or Atom Feed
Feed Location http://www.theregister.co.uk/headlines.atom
Feed Title www.theregister.com - Articles
Feed Link https://www.theregister.com/
Reply 0 comments