Threats · 94 days ago
SRG is lowering the bar for extortion. It no longer needs to lock up systems first; it can win by getting an employee to start a live support session and then quietly take data through that trusted channel.
The group now poses as internal IT or security, uses screen-sharing, and pushes a legitimate remote-access tool into the session. The reporting says SRG has moved away from encryption entirely and is using this pure exfiltration model across victims instead of depending on malware or file encryption.
That shifts the defender's problem from noisy ransomware recovery to trust abuse. If staff will join a screen-share or install remote-support software for an impostor, SRG can scale the same play across more targets with far less friction.
6 sources covering this story
Silent Ransom Group: What You Need to Know
Examining the Silent Ransom Group, a financially motivated cybercrime gang that has been stealing data from companies and demanding payment.
Who Runs the Ransomware Group ‘The Gentlemen?’
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid…
Silent Ransom Group Hits US Law Firms in Escalating Attacks
The financially motivated group is combining vishing, IT impersonation, and in-person office intrusions to steal data and extort victims.
Silent Ransom Group Uses DNS Fast Flux in Attacks
Focusing on hacking law firms in the US, the ransomware group relies on fast flux to hide its C&C infrastructure.
Silent Ransom Group targets law firms with fake IT support calls
The Silent Ransom Group extortion gang is actively targeting U.S.
Cybercriminals, part of a gang known as Silent Ransom Group, have sent people pretending to be IT support employees to law firms' offices, where the criminals have stolen data using USB drives or remote access tools.
Part of the PlainSec briefing for 2026-06-09