Features 27.08.2026

AI Autopsy: Silent Ransom Group Resurrects Old-School Attacks

Hackers are in the building. What next?

Danny Bradbury asks what CISOs should do when the enemy gets too close for comfort

We’re used to hackers rattling our digital doorknobs every day, but it’s been a while since they turned up in person. Silent Ransom Group (SRG) has bucked the trend with an old-school technique: operatives arrive in real life with a USB key in their hand and malice on their mind.

The group emerged from the Conti syndicate’s 2022 collapse and is also tracked as Luna Moth and Chatty Spider. Stealth is its primary focus. It deploys no ransomware encryption and routes installation links through Privnote’s self-destructing messaging service to strip forensic artefacts. That means it flies under the radar of many threat detection systems.

For law firms in particular such techniques have proved devastating.

From phishing to vishing

SRG began life using fake email alerts to lure victims into providing account details. Then in June, Mandiant documented the group impersonating victims’ own internal IT helpdesk staff on voice calls. The tooling is deliberately mundane: operatives have targets install commercial remote-support software such as AnyDesk, Zoho Assist and Bomgar. Endpoint security rarely flags these because legitimate IT teams use them daily.

The cybercrime group works incredibly quickly. Mandiant saw the full attack sequence from first contact to extortion demand completed in under an hour. By late May 2026 its extortion site listed material from at least 38 law firms and over 100 organisations across various sectors.

Let’s get physical

The digital attack is impressive on its own, but the escalation drawing the most attention is the physical fallback. When remote social engineering fails, operatives posing as IT support enter offices and connect USB drives directly to workstations to download data.

“You need to correlate physical access logs with digital activity” FC

Whether this way of doing things can last is contested. Josh Corman, a former chief security officer who is now executive in residence for public safety and resilience at the Institute for Security and Technology, is sceptical.

“It introduces a level of personal physical risk for the attacker in an era where there’s such an abundance of soft targets,” he tells Assured Intelligence. “It doesn’t scale, it’s personally risky, and I think once one or two get caught, you may see that operational pattern change.”

Either way, the physical vector removes the last reliable detection chokepoint; firewalls, EDR and email gateways see nothing once an operative is past reception. Physical infiltration specialist Jenny Radcliffe sees the convergence as predictable.

“This points to a fundamental problem with the entire security industry that is often still far too segmented to be effective,” she tells Assured Intelligence. “Security needs to be seen as a holistic threat to the entire business. It can be breached many ways and every department needs to know and care about it.” Marketing security exclusively to CISOs, she argues, produced the silo SRG now exploits.

Protection must span both the digital and the physical realms, say experts. For example, employees getting a remote support call should verify the ticket number and call back using a known, internal directory number.

Extending zero trust to the building

Beyond protecting against phone and email-based social engineering attacks, though, the framework most CISOs already run for digital identity has to reach the front door.

“Implement a zero trust policy for physical access that mirrors digital zero trust: never trust, always verify,” says “FC”, former head of offensive research at Raytheon and now co-founder of social engineering-focused penetration testing company Cygenta.

Treat a visitor badge, a maintenance uniform, or a vendor van as no more authoritative than an unverified email, he tells Assured Intelligence. In practice this means a process control with no exceptions. Pre-negotiate some kind of visual credential or dynamic code known only to the legitimate vendor and the site manager, FC advises.

“You need to be thinking, is somebody able to see over my shoulder?” Laura Payne

This playbook only works if staff face no consequences for politely halting an interaction while checks complete, warns Radcliffe.

The Institute for Security and Technology’s Corman goes one step further, advising that companies create incentives. Many companies he’s worked with do that by running a tip line. “By submitting to those, you get entered into a competition to get a gift card,” he says. “This is a way to make every single employee from the top to the bottom of the organisation more security conscientious.”

Companies should also rehearse escalation paths like fire drills. “‘See something, say something’ only works if it’s followed by ‘do something’,” Corman adds.

In an era of hybrid work, physical security can’t stop at the lobby. Mandiant saw the attackers targeting workers’ personal devices via Zoom calls. It’s conceivable that a determined attacker might also gain physical access to such a device.

Remote workers must therefore be aware of their surroundings to avoid physical breach, warns Laura Payne, who leads cybersecurity advisory work at Toronto-based cybersecurity consultancy White Tuque.

“You need to be thinking, is somebody able to see over my shoulder?” she tells Assured Intelligence. “Am I working on something that’s too sensitive to be out in public? Am I having a phone conversation that people can overhear?”

Merging physical and digital protection

So how can companies merge physical with technological protection? The Institute for Security and Technology’s Corman says that people can be your sensors in the corridors just as software can be your sensor on the network. EDR agents logging every USB-enumeration event establish the baseline needed to flag anomalous insertions, he adds.

There are also tools to lock down USB ports, says White Tuque’s Payne. However, they’re not perfect, she warns. Expert hackers will insert devices that look like mice or keyboards rather than removable storage.

“The second stage is having endpoint detection that is going to be looking for that suspicious behaviour of large file movements,” Payne adds.

Cygenta’s “FC” adds that technical and physical security can inform each other. “To see physical exfiltration, you need to correlate physical access logs with digital activity,” he explains. “If a badge swipe occurs at a server room at 2am, and a USB device is plugged into a workstation five minutes later, that is your alert.”

Time for take aways

Blending digital and physical protection shouldn’t just be the CISO’s job, says Radcliffe. “A CISO has enough to contend with without being an expert in organisational culture and security awareness as well, so there need to be people within the business tasked with the continuous education of staff and incorporating security into the general, everyday conversation,” she says.

“Security needs to be seen as a holistic threat to the entire business” Jenny Radcliffe

White Tuque’s Payne advocates “fusion centres”. “It’s the idea of bringing together different departments that have some sort of security responsibility and having them do a better job of sharing intelligence and designing controls that actually work across the different spectrums,” she says. In this kind of initiative, facilities might work together with the IT security team.

However, this is a heavy lift, and many companies haven’t yet achieved that kind of coordinated effort. In the absence of such a top-down, enterprise-sponsored activity, there are still things organisations can do to blend physical and digital security

Radcliffe advises companies to build discussions about security into team briefings and meetings. “Nominating someone different for each meeting to bring up a ‘point of security moment’ costs nothing and leads to awareness and discussion,” she says. That kind of show-and-tell example could be something as simple as a news article, or even a scene from a movie.

Identity verification is another defence against SRG-style attacks, but it isn’t the only step companies must take to protect themselves. Verification is now a cross-departmental capability, not simply a technology purchase.

Latest articles

Be an insider. Sign up now!