Threat Insight
Russian Silent Ransom Group Combines Humint and Cyber Extortion
Members of a Russia-based cyberextortion gang plotted to send operatives into U.S. law firms, kidnap business executives and even recruit military personnel to spy on submarine-based nuclear forces, according to leaked chats.[1]
Silent Ransom Group is a cyber extortion group that has been active since 2022. The core members of the group likely include former members of the now defunct Conti ransomware syndicate. The group do not deploy ransomware, but instead rely on data leak only extortion, often targeting law firms and other organizations that would suffer a lot of damage if confidential client information was leaked.[2] [3]
Truesec has already reported how Silent Ransom group have begun imitating Russian intelligence services by recruiting “disposable” agents via Telegram to infiltrate physical buildings of potential victims to insert USB drives with malicious code.
The leaked chats have now revealed that the group has internally discussed other uses for such recruited agents, including physical threats to leadership teams and their families to coerce victims to pay, and to solicit intelligence from US military personnel, via sexual encounters. The last was clearly intended to be used to gather information that could be sold to the Russian government.[1]
Assessment
For a long time it has been observed that cybercriminals often copy methods used by Russian intelligence services. Now it seems that some cybercrime groups are beginning to copy their method of recruiting agents and insiders via Telegram too.
The majority of Russian ransomware groups still rely on tried and tested methods of exploiting exposed credentials and unpatched VPN applications to deploy ransomware. But it is clear that some groups are now exploring combining data leak extortion with physical threats. This is not the first time ransomware criminals have attempted to coerce victims to pay the ransom demanded, but in the past this has been empty threats as cybercriminals had no way to realize the threats.
It is not clear how much this chat actually represent concrete planning or just idle chat, but it’s a clear example of the blurring of lines between physical and cyber threats, just as between state and criminal activities. It is still remarkable that an organized cybercrime group has at least considered hiring agents online to entrap soldiers for espionage purposes and then sell information to the Russian government.
References
[1] https://therecord.media/leaked-chats-show-russian-extortion-gang-sending-agents-to-law-firms
[2] https://www.truesec.com/hub/blog/silent-ransom-group-targets-law-firms
[3] https://www.ic3.gov/CSA/2026/260526.pdf
Stay ahead with cyber insights
Newsletter
Stay ahead in cybersecurity! Sign up for Truesec’s newsletter to receive the latest insights, expert tips, and industry news directly to your inbox. Join our community of professionals and stay informed about emerging threats, best practices, and exclusive updates from Truesec.
Your current browser privacy settings may be preventing this form from loading properly. To continue, please allow cookies/tracking for this site or temporarily disable strict privacy protection, then refresh the page.
If you’re still experiencing issues, please contact us at hello@truesec.com