Daily MaverickK-WORD: Private conversation is no shield for racist language such as the k-word, SCA rulesESPNOffseason questions for eliminated teams: What's next for the Yankees?ESPN DeportesLamine, Fermín: ¿cuánto subió el valor de jugadores de Barcelona?The Jerusalem PostUS State Department restores Israel to highest anti-trafficking ranking for first time since 2021InquirerMarcos’ net satisfaction rate dips to ‘poor’ in Q3 2026 — SWSZDF heuteEntdecken Sie das ZDF-NachrichtenstudioEngadgetForza Horizon 6 is coming to PS5 on January 26Radio-CanadaLa commissaire aux langues officielles demande d’encadrer l’usage de l’IACBS NewsTrump promises not to resume Iran strikes before midterm electionsDeadlineSkydance’s JB Perrette Makes First Moves After Re-Upping ContractCNN بالعربيةإعصار "إيساياس" يقترب من فلوريدا.. طوابير وقود ورفوف متاجر فارغةABC News (Australia)'Cheaper to buy everyone new TVs' as regions lose terrestrial channels
The Daily Newsstand · Free, Always
Thursday, October 8, 2026

Money trail backs leaked chats from extortion crew that walks into US law firms

Translate

Researchers corroborate parts of Silent Ransom Group dump detailing crypto payouts, cash brokers, and recruitment

Cryptocurrency transactions lend credibility to parts of a purported leak from Russian extortion crew Silent Ransom Group (SRG), according to blockchain researchers.

Chainalysis said some wallet addresses in the material match its existing intelligence, although it could not authenticate the entire collection.

It posted: "While we cannot speak to the totality of claims documented in the leak, we can confirm that certain leaked SRG addresses sit downstream of millions of dollars in ransomware payments that SRG has extorted from victims."

REG AD

Despite its name, SRG is known for stealing data and demanding payment rather than deploying ransomware. Its methods include callback phishing and physical intrusions.

REG AD

The FBI warned in May that people posing as IT support staff were entering law offices and copying files onto USB drives.

Chainalysis said the transaction histories of two SRG wallet addresses detailed hundreds of thousands of dollars' worth of funds sent from the wallet of a known SRG member.

The company believes the funds it observed flowing through the leaked addresses came from a large extortion payment made by a victim in mid-2026, and were used to pay for SRG's expenses, such as members' wages and IT infrastructure.

"Our confidence stems from the leaked addresses' transaction history," said Chainalysis. "Several payment addresses contained within the leaks source their funds from confirmed SRG ransom payments.

"For example, one of the Silent members' wallets specified in the leaked chats is funded entirely from a $10 million+ victim payment that SRG collected in mid-2026, and which we were tracking before the leak."

Blockchain analytics company Crystal Intelligence separately examined the leaked chats and traced payments to wallets identified in them.

The chats claim SRG received about $207 million from 27 firms between April and September 2026. Crystal could not verify that total, although it traced funds to an upstream collection wallet that received about 2,675 Bitcoin over its lifetime.

Crystal identified a range of ways SRG spent this money. Sometimes the funds would be sent directly to affiliates, but the group had ways of swapping the crypto for cash they could actually use.

REG AD

According to Crystal's analysis, the group used instant exchangers, services that swap crypto for cash sent to Russian bank cards, and for larger deposits, a Moscow-based broker named "Zhenya" who provided the group with physical cash in exchange for crypto.

The leaked chats suggest members suspected Zhenya of skimming money through the exchange rate, Crystal said.

Crystal said the chats identified a Bitcoin-to-Zelle service advertised on Telegram as SAFU Exchange. Its database associates the same handle with a Georgia-based exchange it describes as unlicensed and sanctions-flagged.

The riskiest of its payment methods was reserved for smaller sums paid directly to the likes of "field agents and document forgers," who received their payments directly into their exchange wallets.

Crystal said these were regulated exchanges that verify customers' identities.

"This is the network's weakest point, and the most direct route for law enforcement to identify the people behind the handles," it said.

According to Crystal, the chats included advice to buy property in person and discussions of purchasing new-build homes and sports cars.

They said to use mortgages for the homes and, if any banks asked questions about the source of the money, to tell them it was an inheritance or a gift, or to produce a fake loan agreement.

REG AD

The material appeared online this week under the title "The Luna Moth Files," a reference to another name researchers use for SRG.

SRG has been active since around 2022 and has maintained a consistent focus on law firms, although it has branched out to other types of organizations too.

The group's usual method is callback phishing. Presenting as IT support staff, they convince marks to return their calls and grant remote access to their desktop sessions, running various tools to steal data.

The Luna Moth Files website claims the material contains nearly 5,700 internal messages identifying senior members and field agents. Those identities have not been independently verified.

These "field agents" are the individuals who were recruited to walk into US law offices to steal data via a thumb drive.

Crystal's analysis of the chat logs concluded that these "field agents" were recruited on Russian-language job boards.

Job listings promised $300+ per night for "nightclub promoters," although respondents were instead pushed into the physical intrusion line of work.

The FBI's May advisory renewed its warning about SRG following fresh reports of attacks that spring. It did not disclose how many incidents involved physical intrusions. ®

View the original on The Register →

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.