Silent Ransom Group Internal Data Leaked on 'Luna Moth Files' Site

Leaked 'Luna Moth Files' Expose Silent Ransom Group Payments

HIGH
October 10, 2026
5m read
Threat ActorData BreachThreat Intelligence

Related Entities

Threat Actors

Silent Ransom Group (SRG)

Other

Chainalysis Fox RothschildJones Day

Full Report

Executive Summary

An unknown party has published a trove of data allegedly belonging to the Silent Ransom Group (SRG), a notorious cyber-extortion entity, on a website named "The Luna Moth Files." The leak, first reported on October 9, 2026, purports to expose the inner workings of the group, which focuses on extorting law firms. The data includes internal chat logs, ransom demands, and, crucially, cryptocurrency wallet addresses. Blockchain intelligence firm Chainalysis has lent credibility to the leak by confirming that wallet addresses within the dataset are linked to known ransomware payments, including one victim payment of $10 million made in mid-2026.

Threat Overview

The Silent Ransom Group, also known by the moniker Luna Moth, operates a data-theft-extortion model, forgoing encryption. The group's modus operandi, as previously detailed in a May FBI alert, involves highly targeted social engineering campaigns against law firm employees. These campaigns often blend emails, phone calls (vishing), and even in-person visits to trick victims into installing software that provides initial access to the firm's network. Once inside, SRG exfiltrates sensitive client data and demands multi-million dollar ransoms to prevent its public release.

The "Luna Moth Files" leak represents a potential 'doxxing' of the threat group itself, offering researchers and law enforcement a rare, albeit unverified, window into their operations, communication, and finances. The validation by Chainalysis suggests the financial data, at a minimum, is legitimate.

Technical Analysis

SRG's TTPs are centered on sophisticated social engineering and data theft, rather than the deployment of traditional ransomware.

MITRE ATT&CK Techniques

  • T1598 - Phishing for Information: SRG's primary initial access method involves multi-faceted phishing and vishing campaigns to gather information or trick users.
  • T1204.002 - Malicious File: The social engineering campaigns aim to convince a target to execute a malicious file, which establishes a foothold on their system.
  • T1059.005 - Visual Basic: Previous analysis of Luna Moth campaigns has shown the use of VBS files for execution after initial access.
  • T1048 - Exfiltration Over Alternative Protocol: The group's primary goal is data exfiltration. They use common protocols to transfer large volumes of stolen data to their own servers.
  • T1657 - Financial Theft: The entire operation is a form of financial theft, where the 'stolen' asset is data, and payment is extorted under threat of public release.

Impact Assessment

The leak's primary impact is on the Silent Ransom Group itself, exposing its operations and potentially aiding law enforcement in identifying its members. For the victimized law firms (including previously linked firms like Fox Rothschild and Jones Day), the leak may bring renewed attention to their breaches. The confirmation of a $10 million payment underscores the immense financial success of these targeted extortion campaigns and the pressure firms are under to pay. This leak could embolden other victims to come forward or, conversely, make future victims more hesitant to negotiate, knowing the group's internal data could be exposed.

IOCs — Directly from Articles

The articles mention the existence of cryptocurrency wallet addresses in the leak but do not list them publicly.

Cyber Observables — Hunting Hints

To detect activity associated with the Luna Moth / Silent Ransom Group TTPs, security teams at law firms should hunt for:

Type
file_name
Value
*.vbs
Description
Monitor for the execution of Visual Basic scripts, especially those downloaded from the internet or email attachments.
Context
EDR logs, process creation logs (Event ID 4688)
Confidence
high
Type
process_name
Value
wscript.exe or cscript.exe
Description
These processes are used to run VBS files. Look for them being launched by unusual parent processes like OUTLOOK.EXE or a web browser.
Context
EDR logs, SIEM
Confidence
high
Type
network_traffic_pattern
Value
Large outbound transfers to new domains
Description
A user workstation suddenly uploading gigabytes of data to a recently registered domain is a major red flag for data exfiltration.
Context
Proxy logs, firewall logs, NetFlow data
Confidence
high
Type
log_source
Value
Building access control logs
Description
Correlating physical access logs with cyber activity could help identify the in-person social engineering component of SRG's TTPs.
Context
Physical security systems, SIEM
Confidence
low

Detection & Response

  • Endpoint Detection and Response (EDR): Deploy EDR to detect the execution of suspicious scripts (.vbs) and the processes they spawn. EDR can block these actions and provide visibility into the attacker's post-compromise activities.
  • Email Security: Use advanced email security gateways to detect and block sophisticated phishing and spear-phishing emails. Analyze emails for signs of social engineering, such as urgent requests or impersonation.
  • User Training: Given the reliance on social engineering, continuous user training is paramount. Employees must be trained to be suspicious of unsolicited calls and emails requesting them to install software or provide credentials. This is a core part of D3FEND User Training (D3-UT).

Mitigation

  • Application Control: Implement application allowlisting to prevent the execution of unauthorized scripts and executables, such as the VBS files used by SRG. This is an application of D3FEND Executable Allowlisting (D3-EAL).
  • Data Loss Prevention (DLP): Deploy DLP solutions that can detect and block large-scale exfiltration of sensitive documents, especially those containing client data or PII.
  • Principle of Least Privilege: Restrict user access to data. An associate working on one case should not have access to the files for every case in the firm. This limits the amount of data an attacker can steal if they compromise a single account.
  • Incident Response Plan: Have a well-defined incident response plan that specifically addresses data extortion scenarios, including criteria for engaging with law enforcement and making decisions about ransom payments.

Timeline of Events

1
May 1, 2026
The FBI issues a warning about the Silent Ransom Group's activities targeting law firms.
2
October 7, 2026
Chainalysis reports it has analyzed and linked leaked cryptocurrency wallets to known ransomware payments.
3
October 9, 2026
News breaks about 'The Luna Moth Files' website leaking internal data from the Silent Ransom Group.
4
October 10, 2026
This article was published

MITRE ATT&CK Mitigations

As the primary vector is social engineering, training users to spot and report phishing and vishing is the most critical defense.

Using application control to block the execution of unauthorized scripts like .vbs files can break the attack chain.

Implementing data loss prevention and egress filtering can detect or block the exfiltration of large volumes of sensitive data.

D3FEND Defensive Countermeasures

The Silent Ransom Group's attack chain relies on convincing a user to run a malicious file, often a VBS script. Application allowlisting is a powerful countermeasure that can disrupt this TTP. By configuring endpoints to only permit the execution of known, signed, and approved applications and scripts, the malicious payload would be blocked from running, even if the user clicks on it. For an environment like a law firm, a baseline of approved software can be established, and any deviation (like a .vbs file downloaded from the internet) would be prevented. This shifts the security posture from trying to detect 'bad' to only allowing 'good,' which is highly effective against this type of attack.

Because SRG's model is built on sophisticated social engineering that includes phone calls and potentially in-person visits, technical controls alone are insufficient. A continuous, targeted training program is essential. This program must educate employees at law firms about the specific tactics used by groups like SRG. It should include simulations of vishing (voice phishing) calls and clear procedures for verifying unusual requests, especially those involving the installation of software or providing credentials. Employees should be empowered and encouraged to report any suspicious contact to the security team immediately, creating a human sensor network that is critical for detecting these highly targeted campaigns.

The core of SRG's business is data exfiltration. Detecting this activity is key to stopping a successful extortion event. User Data Transfer Analysis involves monitoring and baselining the volume and type of data that users typically transfer out of the network. A Data Loss Prevention (DLP) or network analysis tool can be configured to alert when a user workstation begins uploading gigabytes of data to an unknown cloud storage provider or external server, especially if this behavior is anomalous for that user. For a law firm, specific DLP rules can be created to detect the mass exfiltration of documents marked 'attorney-client privilege' or containing sensitive case information. This provides a last line of defense to detect a breach in progress.

Timeline of Events

1
May 1, 2026

The FBI issues a warning about the Silent Ransom Group's activities targeting law firms.

2
October 7, 2026

Chainalysis reports it has analyzed and linked leaked cryptocurrency wallets to known ransomware payments.

3
October 9, 2026

News breaks about 'The Luna Moth Files' website leaking internal data from the Silent Ransom Group.

Sources & References

Leaked Data Exposes Millions Paid to Silent Ransom Group
ProgramBusiness.com (programbusiness.com) •October 9, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

Threat ActorExtortionData LeakLegal ServicesChainalysisCryptocurrency

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.