Back to Intelligence

SILENTRANSOMGROUP Leak-Site Activity: 3 New Listings — Legal & Professional Services Targeting Analysis and Detection Guidance

SA
Security Arsenal Team
October 6, 2026
11 min read

Classification: TLP:CLEAR | Publication Date: 2026-10-06 | Source: ransomware.live leak-site monitoring (single-source for some listings — see Sourcing & Verification) | Nature of data: Unverified threat-actor claims

SILENTRANSOMGROUP Leak-Site Activity: 3 New Listings — Legal & Professional Services Targeting Analysis and Detection Guidance

Executive Summary

On 2026-10-05, the ransomware/extortion group tracked as SILENTRANSOMGROUP published three new listings on its dark web leak site, according to ransomware.live monitoring. The group claims to have compromised the following organizations:

  • Nelson Mullins Riley & Scarborough (Professional Services, US)
  • Sheppard, Mullin, Richter & Hampton (Professional Services, US)
  • A...n (sector and country not identified in the listing)

Two of the three named organizations are large US law firms, consistent with a sector-level interest in professional services — organizations that hold concentrated volumes of attorney-client privileged material, M&A data, litigation strategy, and regulated PII. If the claims were accurate, that data profile is highly leverageable for extortion. These are unverified criminal accusations, not confirmed breaches. All three listings currently rest on a single crawler source. Enterprise security teams — particularly at law firms, accounting firms, and consultancies — should treat this as a trigger for proactive hunting against SILENTRANSOMGROUP's known tradecraft, not as confirmation of any specific incident.

Sourcing & Verification

  • 0 of 3 listings were independently observed by a second leak-site crawler. All 3 listings are single-source, appearing on ransomware.live only. We cannot yet confirm the postings exist as described, let alone that any intrusion occurred.
  • Inclusion in this briefing reflects the threat actor's claim only. A leak-site posting is an accusation by a criminal actor and is not confirmation of a breach. Ransomware groups have historically exaggerated, fabricated, or recycled victim claims.
  • A named organization may dispute a listing. A denial is likewise not proof the claim is false — disclosure obligations vary by jurisdiction and sector, and not every incident is reportable. Neither silence nor denial settles the question. Only the organization itself or its regulator can confirm whether an incident occurred.
  • Security Arsenal will publish corrections as warranted and welcomes contact from any named organization at security@securityarsenal.com.

Threat Actor Profile — SILENTRANSOMGROUP

SILENTRANSOMGROUP is a financially motivated extortion actor. The assessment below reflects publicly reported tradecraft and should be treated as general threat-actor knowledge — we have no evidence tying any specific technique to the listings above.

  • Aliases / overlap: The name is used across tracking communities with limited public clustering. Activity under this branding has shown overlap with data-theft-first extortion crews (sometimes tracked alongside "Silent Ransom" / callback-phishing-style operations). Attribution confidence for the brand itself remains low-to-moderate; treat the leak site as an extortion brand rather than a stable, well-mapped group.
  • Operating model: Assessed as a closed or semi-closed operation rather than a broad open RaaS program, based on low posting volume and selective victimology. Low volume with high-value targets is characteristic of quality-over-quantity extortion crews.
  • Extortion approach: Double extortion — data theft first, threats to publish second. Groups in this lineage are frequently data-extortion-primary, sometimes skipping encryption entirely, which defeats backup-centric defenses. Defenders must assume exfiltration, not encryption, is the main event.
  • Typical ransom demands: Historically calibrated to victim revenue; professional-services victims typically see demands in the mid-six to low-seven figure range, with negotiation pressure driven by confidentiality exposure rather than operational downtime.
  • Initial access methods (reported across the broader actor cluster):
    • Callback phishing / social engineering — lure emails prompting the victim to call a number, leading to guided installation of remote access tooling (AnyDesk, ScreenConnect, Zoho Assist).
    • Phishing with malicious attachments — macro-enabled documents or ISO/LNK loaders.
    • Edge-device exploitation — VPN concentrators, firewalls, and remote management services.
    • RDP exposure — brute forcing or valid-account access to internet-facing RDP.
  • Dwell time: Reported dwell time for data-extortion actors in this class is short-to-moderate (days to roughly two weeks) — they prioritize rapid data identification and exfiltration over persistence depth.

Current Campaign Analysis

Sectors targeted (per the listings): Professional Services (2 of 3 listings, both US law firms); one listing with no sector identified.

Geographic concentration: United States, exclusively among listings with an identified country.

Victim profile: Both named professional services organizations are large, multi-office law firms — enterprises plausibly in the hundreds-of-attorneys class with revenues in the hundreds of millions of dollars. This fits a deliberate pattern: law firms aggregate their clients' most sensitive data, making them a force multiplier for extortion leverage (a single compromise theoretically exposes many downstream clients' matters).

Posting frequency / escalation: Three listings on a single day (2026-10-05) after a quiet period suggests either a batch-posting behavior — accumulating access and publishing in waves to maximize pressure — or opportunistic timing. A one-day cluster of same-sector listings is a classic extortion tactic: it signals to the sector that "your peers are on this list too."

CVE linkage (hypothesis only): We have no evidence tying any specific CVE to these listings. However, SILENTRANSOMGROUP-class actors routinely exploit internet-facing edge and management infrastructure, and several CISA KEV entries with confirmed ransomware use represent plausible sector-level exposure for professional services firms:

  • CVE-2026-50751 (Check Point Security Gateway, improper authentication in IKEv1) — VPN gateway compromise is a direct path to valid-network access matching this actor class's profile.
  • CVE-2026-20316 (Cisco Secure Firewall Management Center, hard-coded password) — management-plane takeover of security infrastructure.
  • CVE-2026-59310 (VMware vCenter path traversal) — vCenter access enables mass data access and, in encrypting scenarios, mass detonation.
  • CVE-2026-63077 (JetBrains TeamCity deserialization) — build-server compromise as a software supply-chain foothold.
  • CVE-2026-48027 (Nx Console embedded malicious code) — developer-workstation supply-chain vector.

Treat these as prioritized patch targets because they are actively exploited by ransomware actors broadly — not as attributed initial access vectors for any organization named in this briefing.

Detection Engineering

The following detections target this actor class's documented playbook: callback-phishing-driven remote access tool installation, edge/VPN access, legitimate-tool lateral movement (PsExec/WMI), and pre-extortion data staging.

YAML
---
title: Remote Access Tool Installation Consistent With Callback Phishing Intrusion
id: 8f2a1c3e-7b41-4d9a-a2e6-srg000000001
status: experimental
description: Detects installation or execution of remote access tools (AnyDesk, ScreenConnect, Zoho Assist, TeamViewer, Atera, Splashtop) commonly deployed via callback phishing social engineering used by SilentRansomGroup-class actors.
references:
  - https://securityarsenal.com/darkside
author: Security Arsenal Threat Intelligence
date: 2026/10/06
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    Image|endswith:
      - '\AnyDesk.exe'
      - '\ScreenConnect.ClientService.exe'
      - '\ScreenConnect.WindowsClient.exe'
      - '\TeamViewer.exe'
      - '\AteraAgent.exe'
      - '\Splashtop.exe'
      - '\ZohoMeeting.exe'
      - '\ConnectWiseControl.exe'
  selection_cmd:
    CommandLine|contains:
      - 'anydesk'
      - 'screenconnect'
      - 'zohoassist'
  condition: 1 of selection_*
falsepositives:
  - Legitimate IT administration - baseline approved RMM tooling and alert on deviations
level: high
tags:
  - attack.command_and_control
  - attack.t1219
---
title: PsExec or WMI Remote Execution for Lateral Movement
id: 8f2a1c3e-7b41-4d9a-a2e6-srg000000002
status: experimental
description: Detects PsExec service installation and WMI-based remote process execution consistent with pre-ransomware lateral movement tradecraft.
references:
  - https://securityarsenal.com/darkside
author: Security Arsenal Threat Intelligence
date: 2026/10/06
logsource:
  product: windows
  category: process_creation
detection:
  selection_psexec:
    - Image|endswith: '\PSEXESVC.exe'
    - OriginalFileName: 'psexesvc.exe'
    - CommandLine|contains:
        - 'psexec'
        - '\\*\ADMIN$'
  selection_wmi:
    Image|endswith: '\WmiPrvSE.exe'
    CommandLine|contains:
      - 'cmd.exe'
      - 'powershell'
      - 'wscript'
  condition: selection_psexec or selection_wmi
falsepositives:
  - Administrative tooling (SCCM, PDQ) - whitelist known deployment accounts and hosts
level: high
tags:
  - attack.lateral_movement
  - attack.t1569.002
  - attack.t1047
---
title: Data Staging and Compression Prior to Exfiltration
id: 8f2a1c3e-7b41-4d9a-a2e6-srg000000003
status: experimental
description: Detects archive creation using 7-Zip or WinRAR with password protection and multi-volume output, a hallmark of pre-extortion data staging by double-extortion actors.
references:
  - https://securityarsenal.com/darkside
author: Security Arsenal Threat Intelligence
date: 2026/10/06
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    Image|endswith:
      - '\7z.exe'
      - '\7za.exe'
      - '\rar.exe'
      - '\winrar.exe'
  selection_flags:
    CommandLine|contains:
      - ' -p'
      - ' -v'
      - ' -m0=lzma2'
      - '-hp'
  filter_paths:
    CommandLine|contains:
      - '\Program Files\7-Zip\'
    ParentImage|endswith: '\explorer.exe'
  condition: selection_img and selection_flags and not filter_paths
falsepositives:
  - Backup operations, developer packaging - tune per host role and scheduled task context
level: medium
tags:
  - attack.collection
  - attack.t1560.001
  - attack.exfiltration
KQL — Microsoft Sentinel / Defender
// Hunt: Pre-extortion staging & exfiltration chain (7-day lookback)
// Correlates: RMM tool execution -> archive creation -> large outbound transfer
let Lookback = 7d;
let RMM = dynamic(["anydesk.exe","screenconnect.windowsclient.exe","teamviewer.exe","splashtop.exe","ateraagent.exe","zohoassist.exe"]);
let Archivers = dynamic(["7z.exe","7za.exe","rar.exe","winrar.exe"]);
let RMMHosts =
    DeviceProcessEvents
    | where Timestamp > ago(Lookback)
    | where FileName in~ (RMM)
    | summarize FirstRMM=min(Timestamp) by DeviceName, InitiatingProcessAccountName;
let ArchiveEvents =
    DeviceProcessEvents
    | where Timestamp > ago(Lookback)
    | where FileName in~ (Archivers)
    | where ProcessCommandLine has_any (" -p", " -v", "-hp")
    | project ArchiveTime=Timestamp, DeviceName, InitiatingProcessAccountName, ProcessCommandLine, FolderPath;
let BigOutbound =
    DeviceNetworkEvents
    | where Timestamp > ago(Lookback)
    | where RemoteIPType == "Public"
    | summarize TotalBytesSent = sumif(long(0), true), Connections = count(), Destinations = make_set(RemoteUrl, 20) by DeviceName, InitiatingProcessAccountName, bin(Timestamp, 1h);
RMMHosts
| join kind=inner ArchiveEvents on DeviceName, InitiatingProcessAccountName
| where ArchiveTime > FirstRMM
| join kind=leftouter BigOutbound on DeviceName, InitiatingProcessAccountName
| project DeviceName, InitiatingProcessAccountName, FirstRMM, ArchiveTime, ProcessCommandLine, Connections, Destinations
| order by DeviceName asc, ArchiveTime asc;
PowerShell
# Rapid Triage Script: SILENTRANSOMGROUP Pre-Extortion Indicators
# Run elevated. Checks: new scheduled tasks (7d), unauthorized RMM tools,
# shadow copy tampering, suspicious new local admins, RDP exposure.
$lookback = (Get-Date).AddDays(-7)
$report = @{}

# 1. Scheduled tasks created/modified in last 7 days (persistence/staging)
$report['NewScheduledTasks'] = Get-ScheduledTask | Where-Object {
    $_.Date -and ([datetime]$_.Date) -gt $lookback -and
    $_.TaskPath -notlike '\Microsoft*'
} | Select-Object TaskName, TaskPath, Date, @{n='Action';s={$_.Actions.Execute}}

# 2. RMM tool artifacts (callback-phishing vector)
$rmmPaths = @("$env:ProgramData\AnyDesk","$env:ProgramFiles\ScreenConnect*",
  "$env:ProgramFiles (x86)\ScreenConnect*","$env:ProgramData\TeamViewer",
  "$env:LOCALAPPDATA\AnyDesk","$env:ProgramFiles\Atera Networks*")
$report['RMMArtifacts'] = foreach ($p in $rmmPaths) {
    Get-Item $p -ErrorAction SilentlyContinue | Select-Object FullName, CreationTime, LastWriteTime
}

# 3. Volume Shadow Copy status and recent deletion evidence
$report['ShadowCopies'] = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue |
  Select-Object ID, InstallDate, VolumeName
$report['ShadowDeletionEvents'] = Get-WinEvent -FilterHashtable @{
    LogName='System'; Id=410; StartTime=$lookback
  } -ErrorAction SilentlyContinue | Select-Object TimeCreated, Message

# 4. New local administrators
$report['NewLocalAdmins'] = Get-LocalGroupMember -Group 'Administrators' -ErrorAction SilentlyContinue |
  Select-Object Name, ObjectClass, PrincipalSource

# 5. Internet-facing RDP check
$rdpEnabled = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections).fDenyTSConnections -eq 0
$rdpPort = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name PortNumber).PortNumber
$fwRules = Get-NetFirewallRule -DisplayGroup 'Remote Desktop' -ErrorAction SilentlyContinue |
  Where-Object Enabled -eq 'True' | Measure-Object
$report['RDPExposure'] = [pscustomobject]@{
    RDPConnectionsAllowed = $rdpEnabled
    RDPPort = $rdpPort
    EnabledRDPFirewallRules = $fwRules.Count
}

$report | ConvertTo-Json -Depth 4 | Out-File ".\SRG_Triage_$(Get-Date -Format 'yyyyMMdd_HHmm').json"
Write-Host "[+] Triage complete. Review SRG_Triage_*.json" -ForegroundColor Green

Incident Response Priorities

T-minus detection checklist (what to look for BEFORE encryption or the leak post):

  1. New or unexpected RMM/remote access tools (AnyDesk, ScreenConnect, Zoho Assist) — the single highest-fidelity early indicator for this actor class.
  2. Outbound connections to consumer file-sharing (MEGA, Dropbox, pCloud) or VPS-hosted transfer endpoints from servers.
  3. Archive creation (7z/rar with password or volume flags) on file servers, DMS (iManage/NetDocuments), and mail servers.
  4. New scheduled tasks or services created outside change windows.
  5. vssadmin delete shadows / wbadmin delete / Event ID 410 shadow deletion events.
  6. LSASS access by non-system processes; suspicious use of ntdsutil or volume shadow copies of ntds.dit.
  7. VPN gateway authentication anomalies: logins from unusual geographies/ASNs, especially on appliances pending CVE-2026-50751 or CVE-2026-20316 patching.

Assets this actor class prioritizes for exfiltration: For professional services targets specifically — document management systems (client matter files), email archives of partners, contract repositories, HR/payroll exports, and any data whose confidentiality (not availability) is the leverage. Assume exfiltration is the objective; do not anchor IR on encryption indicators.

Containment actions, ordered by urgency:

  1. Isolate affected hosts from the network (do not power off — preserve memory).
  2. Block identified RMM tool binaries and their domains/IPs estate-wide via EDR and egress filtering.
  3. Force-reset credentials for any account observed in lateral movement; revoke active sessions and VPN tokens.
  4. Disable or patch the edge device suspected as initial access; capture its config and logs first.
  5. Suspend outbound traffic to identified staging destinations; enable TLS inspection logging on remaining egress.
  6. Engage counsel early — for law firm victims, client notification obligations and privilege questions are immediate.

Hardening Recommendations

Immediate (24 hours):

  • Patch or mitigate CVE-2026-50751 (Check Point IKEv1) and CVE-2026-20316 (Cisco FMC hard-coded password) on all perimeter devices; both are CISA KEV with confirmed ransomware use.
  • Block installation/execution of unapproved remote access tools via AppLocker/WDAC or EDR policy — publish an approved-RMM allowlist and alert on everything else.
  • Enforce phishing-resistant MFA (FIDO2) on VPN, remote access, and email; audit for legacy IKEv1/basic-auth paths.
  • Egress-filter outbound traffic to consumer file-sharing and newly registered domains; alert on large sustained uploads from servers.
  • Brief help desks and executives on callback-phishing lures — the human-guided RMM install is this actor class's signature entry.

Short-term (2 weeks):

  • Patch CVE-2026-59310 (vCenter), CVE-2026-63077 (TeamCity), and audit developer tooling exposure given CVE-2026-48027 (Nx supply chain).
  • Segment document management systems and client-matter repositories from general workstation VLANs; require just-in-time elevation for DMS admin access.
  • Deploy the Sigma/KQL detections above into your SIEM with tuned baselines; run the triage script across file servers and DMS hosts as a one-time sweep.
  • Implement Data Loss Prevention or egress volume anomaly detection keyed to archive-creation events on data-bearing servers.
  • Establish immutable, offline backups and an exfiltration-specific IR playbook — backups do not mitigate data-theft extortion.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.