Luna Moth’s Growing Focus on Law Firms
The Advocate welcomes guest author Marc Grens, Co-Founder and President of Chaintrax Cyber, a premier full-service cybercrime resolution platform built on more than a decade of incident response experience at DigitalMint. Under his leadership, Chaintrax Cyber has grown into a trusted partner for organizations navigating ransomware, extortion and crypto-enabled crime, delivering threat actor intelligence, compliant ransom payment services, blockchain and crypto crime investigations, and recovery support.
A serial entrepreneur and active angel investor, Marc has spent more than 25 years growing start-up enterprises, financial services ventures and leading-edge technologies. Before co-founding Chaintrax Cyber, he co-founded DigitalMint and built his career as a portfolio manager, research analyst and investment advisor, holding key positions at Charles Schwab and HighTower Advisors. He now serves on advisory boards for fintech and technology companies.
Marc received his MBA from DePaul University and BA from Illinois State University. A highly sought-after speaker, he regularly lectures on cryptocurrency, blockchain, cybersecurity, anti-money laundering, compliance, crypto crime and ransomware.
Recent reporting from Google Threat Intelligence Group and researchers tracking Silent Ransom Group (SRG), also known as Luna Moth, Chatty Spider and UNC3753, points to an increasingly clear trend: Law firms have become one of the group’s preferred targets.
Luna Moth differs from traditional ransomware operators. Rather than relying on file encryption, the group focuses on social engineering, data theft and extortion. Victims are often contacted through phishing, callback phishing or vishing campaigns, with attackers impersonating IT support personnel to gain access to systems and sensitive information.
Our own analysis of 56 known Luna Moth/Silent Ransom Group victim cases reinforces what recent intelligence reporting has suggested. Of those 56 victims, 43 were in the legal services sector, meaning about 77% of observed victims were law firms or legal service providers.
That level of concentration is unusual. While the group has targeted other industries, the data suggests a deliberate focus on legal organizations. From an attacker’s perspective, the reasoning is straightforward: Law firms hold large volumes of confidential client information, litigation records, financial data, intellectual property and other highly sensitive documents. The potential reputational and legal consequences of a data leak can also create strong pressure to pay extortion demands.
The group’s operations continue to evolve as well. Recent research has indicated the use of fast-flux infrastructure to support leak sites and other operational systems, making takedown efforts more difficult and helping maintain the group’s extortion capabilities.
Taken together, both public reporting and victim data show that Luna Moth is not simply targeting organizations at random. The group’s victimology indicates a clear preference for the legal sector, and our findings suggest that law firms remain at the centre of its operations.
With nearly 77% of observed victims coming from legal services, organizations in the sector should view Luna Moth as a persistent and highly relevant threat.
Connect with a HUB ProEx Specialist to review your policies and identify opportunities to strengthen your risk management approach. View more articles in HUB’s ProEx Advocate Articles & Insights Directory.