Silent Ransom Group, also known as LeakedData, emerged in March 2022 after the Conti ransomware's collapse. This group specializes in data theft and extortion without using traditional ransomware encryption, focusing on pressuring victims to pay ransoms through threats of public data release.
Key insights
•Primarily uses social engineering tactics such as callback phishing and vishing to gain initial access.
•Impersonates IT support to trick employees into granting remote access to systems.
•Utilizes legitimate remote access tools for execution and data exfiltration, employing methods that minimize forensic evidence.
•Maintains a dark web site where stolen data can be publicly leaked if ransom demands are not met.
•Targets a wide range of sectors, particularly focusing on legal firms and healthcare organizations.