Money trail backs leaked chats from extortion crew that walks into US law firms
Researchers corroborate parts of Silent Ransom Group dump detailing crypto payouts, cash brokers, and recruitment
Blockchain researchers Chainalysis have found cryptocurrency transactions that support claims from a purported leak of communications from the Russian extortion crew, Silent Ransom Group (SRG). While they cannot verify the entire leak, they confirm that certain wallet addresses appear downstream of millions of dollars in ransomware payments that SRG has extorted from victims.
Unlike SRG's typical method of stealing data, the crew steals data and demands payment. The FBI warned in May that impostors posing as IT support staff were entering law offices and stealing files. Chainalysis believes funds observed flowing through the leaked addresses came from a large extortion payment made in mid-2026, used to pay for SRG's expenses, including members' wages and IT infrastructure.
Multiple payment addresses traced to confirmed SRG ransom payments were funded entirely from a $10 million+ victim payment made in mid-2026. Crystal Intelligence, another blockchain analytics company, examined the leaked chats and traced payments to these wallets. They found the group spent the money on various things, including sending it directly to affiliates, swapping it for cash using instant exchangers, and using a Moscow-based broker named Zhenya who provided physical cash in exchange for crypto.
The leaked chats also identified a Telegram-advertised Bitcoin-to-Zelle service, associated with a Georgia-based exchange flagged for sanctions. The riskiest payments were made directly to field agents and document forgers, who received funds in regulated exchanges. The leaked chats suggested members suspected Zhenya of skimming money through the exchange rate.
The leaked messages contained advice on buying property in person, purchasing new-build homes, and sports cars, with tips on using mortgages and fake loan agreements to avoid scrutiny. The material was published under the title "The Luna Moth Files." SRG has been active since around 2022, primarily targeting law firms, but has also targeted other organizations.
The crew typically uses callback phishing, posing as IT support staff to gain remote access to victims' desktop sessions and steal data.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.