Silent Ransom Group (SRG), a hacking collective, has been turning up at US offices posing as IT support to install malware and copy files for later extortion.
The Federal Bureau of Investigation said in an alert SRG has operated since 2022 and recently shifted from remote cyber attacks to in-person intrusions, primarily targeting US law firms while warning the medical and insurance sectors may also be at risk.
“The ‘low-tech’ nature of the attack is exactly the point. Criminals do not use advanced techniques because they are fashionable; they use whatever works,” Bogdan Botezatu, senior director of threat research at Bitdefender, told The Independent.
The FBI described SRG’s typical playbook as IT-themed social engineering calls to arrange a visit, followed by an impersonator physically inserting a storage device into a computer to exfiltrate data and then sending ransom demands threatening to publish or sell the stolen material.
The alert sits amid wider shifts in the threat landscape, with defenders adopting AI-powered agent systems, Microsoft has said it uses more than 100 AI agents, while attackers increasingly employ AI too, using voice cloning, deepfakes and automated agents to accelerate credential theft and payload deployment.