Leaked data has shown millions of dollars in extortion payments to a hacking group known for targeting law firms, Chainalysis said.
The data, called the “Luna Moth Files”, was published online earlier this week by unknown people, claiming to be information from inside the Silent Ransom Group, which US authorities have said is linked to Russia.
The data includes chat logs, alleged ransom demands, and dozens of cryptocurrency wallet addresses.
Millions in payments
Chainalysis said some of the addresses in the leaked data were ones it was already tracking, including a $10 million (£7.6m) payment made by a victim to SRG in mid-2026.
“Certain leaked SRG addresses sit downstream of millions of dollars in ransomware payments that SRG has extorted from victims,” Chainalysis said in a social media post on Wednesday.
SRG emerged in March 2022 from the collapse of the Conti ransomware organisation, with the new entity abandoning the use of traditional hacking tools.
Instead, SRG relies on elaborate social engineering ruses to gain access to sensitive systems at large law firms, consistently using legitimate system management software.
Physical intrusions
Beginning in the spring of this year, when remote techniques such as telephone calls or phishing emails do not work, SRG has begun sending operatives to law firms’ premises, posing as the company’s own technical support workers, to attach a storage device to a targeted person’s computer, which copies large amounts of data, the FBI said in an advisory in late May.
SRG demands a ransom to refrain from publishing the stolen data online.
Researchers have estimated that more than 100 law firms in all have had data stolen by the group.