INTEL_REPORT
Mandiant / Google Threat Intelligence Blog · published 6/5/2026, 2:00:00 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms Written by: Chad Reams, Tufail Ahmed, Keith Knapp, Ashley Frazer, Tyler McLellan Introduction From January through May 2026, Mandiant identified a financially motivated data theft extortion campaign executed by the threat cluster UNC3753 (also tracked as "Luna Moth," “Chatty Spider,” and "Silent Ransom Group") targeting dozens of organizations across professional, legal, and financial services in the United Stat…
https://cloud.google.com/blog/topics/threat-intelligence/targeted-campaign-us-law-firms
sha256:7c52a86286bf41f7578fc018ad50204cd0b1a38d16f4c8c12f608c983b96c8b3
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| superops.msi |
| Open → |
| domain | windows365.exe | Open → |
| domain | business-data-leaks.com | Open → |
| domain | itdesk.com | Open → |
| domain | it.com | Open → |
| domain | helpdesk.com | Open → |