An unknown party has published a trove of data allegedly belonging to the Silent Ransom Group (SRG), a notorious cyber-extortion entity, on a website named "The Luna Moth Files." The leak, first reported on October 9, 2026, purports to expose the inner workings of the group, which focuses on extorting law firms. The data includes internal chat logs, ransom demands, and, crucially, cryptocurrency wallet addresses. Blockchain intelligence firm Chainalysis has lent credibility to the leak by confirming that wallet addresses within the dataset are linked to known ransomware payments, including one victim payment of $10 million made in mid-2026.
The Silent Ransom Group, also known by the moniker Luna Moth, operates a data-theft-extortion model, forgoing encryption. The group's modus operandi, as previously detailed in a May FBI alert, involves highly targeted social engineering campaigns against law firm employees. These campaigns often blend emails, phone calls (vishing), and even in-person visits to trick victims into installing software that provides initial access to the firm's network. Once inside, SRG exfiltrates sensitive client data and demands multi-million dollar ransoms to prevent its public release.
The "Luna Moth Files" leak represents a potential 'doxxing' of the threat group itself, offering researchers and law enforcement a rare, albeit unverified, window into their operations, communication, and finances. The validation by Chainalysis suggests the financial data, at a minimum, is legitimate.
SRG's TTPs are centered on sophisticated social engineering and data theft, rather than the deployment of traditional ransomware.
T1598 - Phishing for Information: SRG's primary initial access method involves multi-faceted phishing and vishing campaigns to gather information or trick users.T1204.002 - Malicious File: The social engineering campaigns aim to convince a target to execute a malicious file, which establishes a foothold on their system.T1059.005 - Visual Basic: Previous analysis of Luna Moth campaigns has shown the use of VBS files for execution after initial access.T1048 - Exfiltration Over Alternative Protocol: The group's primary goal is data exfiltration. They use common protocols to transfer large volumes of stolen data to their own servers.T1657 - Financial Theft: The entire operation is a form of financial theft, where the 'stolen' asset is data, and payment is extorted under threat of public release.The leak's primary impact is on the Silent Ransom Group itself, exposing its operations and potentially aiding law enforcement in identifying its members. For the victimized law firms (including previously linked firms like Fox Rothschild and Jones Day), the leak may bring renewed attention to their breaches. The confirmation of a $10 million payment underscores the immense financial success of these targeted extortion campaigns and the pressure firms are under to pay. This leak could embolden other victims to come forward or, conversely, make future victims more hesitant to negotiate, knowing the group's internal data could be exposed.
The articles mention the existence of cryptocurrency wallet addresses in the leak but do not list them publicly.
To detect activity associated with the Luna Moth / Silent Ransom Group TTPs, security teams at law firms should hunt for:
file_name*.vbsprocess_namewscript.exe or cscript.exeOUTLOOK.EXE or a web browser.network_traffic_patternLarge outbound transfers to new domainslog_sourceBuilding access control logs.vbs) and the processes they spawn. EDR can block these actions and provide visibility into the attacker's post-compromise activities.As the primary vector is social engineering, training users to spot and report phishing and vishing is the most critical defense.
Using application control to block the execution of unauthorized scripts like .vbs files can break the attack chain.
Implementing data loss prevention and egress filtering can detect or block the exfiltration of large volumes of sensitive data.
The Silent Ransom Group's attack chain relies on convincing a user to run a malicious file, often a VBS script. Application allowlisting is a powerful countermeasure that can disrupt this TTP. By configuring endpoints to only permit the execution of known, signed, and approved applications and scripts, the malicious payload would be blocked from running, even if the user clicks on it. For an environment like a law firm, a baseline of approved software can be established, and any deviation (like a .vbs file downloaded from the internet) would be prevented. This shifts the security posture from trying to detect 'bad' to only allowing 'good,' which is highly effective against this type of attack.
Because SRG's model is built on sophisticated social engineering that includes phone calls and potentially in-person visits, technical controls alone are insufficient. A continuous, targeted training program is essential. This program must educate employees at law firms about the specific tactics used by groups like SRG. It should include simulations of vishing (voice phishing) calls and clear procedures for verifying unusual requests, especially those involving the installation of software or providing credentials. Employees should be empowered and encouraged to report any suspicious contact to the security team immediately, creating a human sensor network that is critical for detecting these highly targeted campaigns.
The core of SRG's business is data exfiltration. Detecting this activity is key to stopping a successful extortion event. User Data Transfer Analysis involves monitoring and baselining the volume and type of data that users typically transfer out of the network. A Data Loss Prevention (DLP) or network analysis tool can be configured to alert when a user workstation begins uploading gigabytes of data to an unknown cloud storage provider or external server, especially if this behavior is anomalous for that user. For a law firm, specific DLP rules can be created to detect the mass exfiltration of documents marked 'attorney-client privilege' or containing sensitive case information. This provides a last line of defense to detect a breach in progress.
The FBI issues a warning about the Silent Ransom Group's activities targeting law firms.
Chainalysis reports it has analyzed and linked leaked cryptocurrency wallets to known ransomware payments.
News breaks about 'The Luna Moth Files' website leaking internal data from the Silent Ransom Group.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.