Russian Silent Ransom Group Combines Humint and Cyber Extortion

Silent Ransom Group is a cyber extortion group that has been active since 2022. The core members of the group likely include former members of the now defunct Conti ransomware syndicate. The group do not deploy ransomware, but instead rely on data leak only extortion, often targeting law firms and other organizations that would suffer a lot of damage if confidential client information was leaked.[2] [3]

Introduction to Malware Binary Triage (IMBT) Course

Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

Truesec has already reported how Silent Ransom group have begun imitating Russian intelligence services by recruiting “disposable” agents via Telegram to infiltrate physical buildings of potential victims to insert USB drives with malicious code.

The leaked chats have now revealed that the group has internally discussed other uses for such recruited agents, including physical threats to leadership teams and their families to coerce victims to pay, and to solicit intelligence from US military personnel, via sexual encounters. The last was clearly intended to be used to gather information that could be sold to the Russian government.[1]

Assessment

For a long time it has been observed that cybercriminals often copy methods used by Russian intelligence services. Now it seems that some cybercrime groups are beginning to copy their method of recruiting agents and insiders via Telegram too.

The majority of Russian ransomware groups still rely on tried and tested methods of exploiting exposed credentials and unpatched VPN applications to deploy ransomware. But it is clear that some groups are now exploring combining data leak extortion with physical threats. This is not the first time ransomware criminals have attempted to coerce victims to pay the ransom demanded, but in the past this has been empty threats as cybercriminals had no way to realize the threats.

It is not clear how much this chat actually represent concrete planning or just idle chat, but it’s a clear example of the blurring of lines between physical and cyber threats, just as between state and criminal activities. It is still remarkable that an organized cybercrime group has at least considered hiring agents online to entrap soldiers for espionage purposes and then sell information to the Russian government.

References

[1] https://therecord.media/leaked-chats-show-russian-extortion-gang-sending-agents-to-law-firms
[2] https://www.truesec.com/hub/blog/silent-ransom-group-targets-law-firms
[3] https://www.ic3.gov/CSA/2026/260526.pdf

The post Russian Silent Ransom Group Combines Humint and Cyber Extortion appeared first on Truesec.

Article Link: Russian Silent Ransom Group Combines Humint and Cyber Extortion - Truesec