Luna Moth
❔ UnknownMotivation: financialLast active: 2026-09-21First seen: 2026-04-01
0
linked CVEs
Also known as
Silent RansomTG2729SilentRansomGroup
Targeted industries
Business ServicesNot FoundProfessional Services
Targeted regions
DEGBUS
Luna Moth conducts high-tempo callback phishing campaigns targeting legal and financial organizations in the U.S., using social engineering to lure victims into calling fake helpdesk numbers. Attackers impersonate IT staff to install legitimate RMM tools, enabling direct access to victim systems for data exfiltration. The group demands ransoms between $1 million and $8 million, threatening to leak stolen data if payments are not made. Their operations reflect a shift from traditional ransomware tactics to data breach extortion, leveraging trusted systems to evade detection.
Source: misp_galaxy · Collected: 2026-09-22
⚡ Vulnerabilities & Exploits0 CVEs
threat_actor_cve → cves / exploits.cve_ids
No CVE correlation on record for this actor yet.
🔍 Detection Coverage0 Sigma
Derived from linked CVEs — not a direct actor match
No Sigma rules mapped via this actor's CVEs yet.
🧬 YaraComing soon
🛰️ Infrastructure & IOCs10
| ip | 174.169.162.62 | — | 2026-06-05 |
| ip | 192.236.147.131 | — | 2026-06-05 |
| domain | business-data-leaks.com | — | 2026-06-05 |
| ip | 192.236.154.158 | — | 2026-06-05 |
| ip | 64.94.84.97 | — | 2026-06-05 |
| url | https://business-data-leaks.com | — | 2026-06-05 |
| ip | 193.141.60.212 | — | 2026-06-05 |
| domain | privnote.com | — | 2026-06-05 |
| ip | 192.236.146.173 | — | 2026-06-05 |
| ip | 192.236.147.138 | — | 2026-06-05 |
📰 Threat Intel Coverage1
Digest reports mentioning this actor (incl. aliases)
| Ongoing Targeted Campaign Against US Law Firms | Google Cloud Blog | matched as Luna Moth | 2026-06-05 |