< Back to all clusters
[CRIME] · United States, Mexico, Brazil, Argentina, South Korea · 2 sources

Silent Ransom Group uses fast‑flux botnet to extort US law firms

Cyber‑extortion group Silent Ransom Group (SRG) has compromised dozens of U.S. firms between January and May 2026, primarily targeting law firms. Attackers impersonated IT support, sometimes sending operatives to offices to copy data onto USB drives before demanding ransom to delete or withhold public release. The group’s extortion model relies on publishing stolen files on leak sites such as business‑data‑leaks.com.

Research by Resecurity shows SRG runs a professional‑grade fast‑flux botnet that hides these leak sites behind rotating residential IPs in at least 18 countries, including Mexico, Brazil, Argentina and South Korea. By constantly changing IP addresses through compromised home routers, the infrastructure evades takedown by authorities and ISPs. The botnet backs nearly 100 victim companies and has already forced the public exposure of data from at least 38 law firms.

SRG is linked to earlier ransomware campaigns such as BazarCall, Conti and Ryuk, and its tactics include voice‑phishing (vishing) and social‑engineering attacks to gain remote access before exfiltrating data.