Silent Ransom Group leak: agents sent into US law firms
A Russia-based extortion gang planned to place operatives inside US law firms, kidnap executives and recruit military personnel to spy on submarine-based nuclear forces, according to leaked chats reviewed by Recorded Future News.
An unidentified source posted the archive to a custom .onion site in early October without giving a reason. It holds thousands of messages from August 2025 to September 2026. Members discuss dozens of victims, negotiate multimillion-dollar payments and give instructions to US-based operatives they call "agents." Some of the organizations named have not publicly confirmed a breach.
The material is uneven. Records that appear to document real extortion sit next to brainstorming, dropped plans, boasting and violent fantasies. Recorded Future News could not verify whether the most extreme schemes were ever tried.
Independent confirmation
Parts of the leak have been confirmed by outside sources. Blockchain analysis firm Chainalysis reviewed cryptocurrency addresses in the archive and linked them to known extortions by the Silent Ransom Group, also tracked as Luna Moth and Chatty Spider. The company said it could not "speak to the totality of claims" in the archive.
The FBI has also described the group's most unusual tactic for a Russian extortion crew: sending people into victims' offices. A flash alert earlier this year warned that Silent Ransom Group members were posing as IT staff to get physical access to computers.
One negotiation in the chats backs this up. A law firm representative told the extortionists the firm knew someone had entered its New York office and copied files to a flash drive. The firm said its executives had approved $1 million to settle, but wanted proof that all digital and physical copies of its data would be destroyed. It pointed to evidence that the LockBit ransomware gang had not deleted data from victims who paid.
Pizza boxes, masks and fake IDs
Members spent months discussing how to get agents through the door. One suggested buying delivery uniforms and insulated bags, writing: "We buy these insulated bags and uniforms for agents." The plan was for an operative to get past reception with a pizza delivery and then pose as an IT worker in the main office.
Other ideas included custom masks modelled on real lawyers and smart glasses for an agent posing as a client to film inside an office. An earlier shopping list included a $3,200 ultraviolet-capable printer and holographic materials for ID cards. The archive also mentions payments to forgers, one of them in New York.
The chats do not show whether the pizza ruse or the masks were ever used. The general approach of sending impostors into offices does match the FBI's account.
Recruiting through Telegram
The model relied on finding people willing to do the physical work, similar to the disposable agents recruited by Russian and Iranian intelligence services. The group ran paid Telegram ads disguised as ordinary jobs, such as nightclub promotion, courier work and security. The ads appear aimed at Russian speakers.
Recruitment did not go smoothly. A roster lists agents by numbered codes and city, and one entry marks a 17-year-old as ready to work while noting the recruit was underage. One channel name suggests an agent had been caught in Chicago.
In February, the group's apparent leader put the "conversion" rate at about one in 10 recruits. Another member called the process a conveyor belt. Some recruits vanished after being paid or backed out at office entrances, while others were given paid test tasks. It is not clear that every recruit knew the real purpose. One member suggested explaining the full scheme only "to those who we trust fully." Leaders spoke about recruits with contempt, including in racist terms, and discussed tracking them in case they stole from the group or went to the FBI.
A sales pipeline for extortion
Victims moved through stages like a sales funnel: "chat," "offer," "contract" and "gold." In one case, a $100,000 opening offer was mocked as "missing a zero." Later entries climbed through $500,000, $1.5 million, $2.25 million, $3 million and $3.5 million, before a $6 million contract and then "gold."
Across the dozens of firms marked "gold," the archive claims roughly $200 million in settlements. These are the group's own figures and could not be verified. About 50 organizations appear in the records, mostly law firms.
The chats also cover coercion. Senior lawyers and executives, routinely called "oldies," were discussed as targets to follow and study. One exchange proposed photographing a target's school-age child as leverage. Other threads raised a fake escort site, sexual blackmail, kidnapping executives or relatives, and a "punishment" group, with debate over real or fake weapons. Nothing shows these plans were carried out.
Military ambitions
In April, the leader floated targeting a senior employee at a major military contractor working with the US Army, noting the "monetization" would have to differ. Another user suggested the Russian Ministry of Defense could pay, before adding a laughing emoticon. The archive contains no evidence that the ministry contacted, commissioned or paid the group.
A channel created in May discussed recruiting US sailors through gay bars near naval bases to learn about the movements of "submarine-based nuclear forces." The group gathered details on bases and nearby venues, but nothing shows anyone was recruited or that military information was obtained.
Members also warned each other off iPhones, studied arrests of associates and discussed traveling through countries they saw as lower extradition risks, such as Ethiopia. As of September, they were talking about relaunching as Sleepless Threat. "The ultimate goal is to become a social movement or a cult," a senior user wrote in April.
Our Take
The leak suggests that the line between remote intrusion and physical intrusion is getting thinner for some extortion crews. Law firms, which hold sensitive client data and are under pressure to settle quietly, should treat visitors, contractors and walk-in "IT staff" as part of their threat model, not only phishing emails and exposed servers.
The recruitment model also mirrors a wider pattern of criminals paying outsiders and insiders to do hands-on work, as seen in reports of criminals recruiting insiders at logistics firms. The firm that cited LockBit's failure to delete data also shows why paying a ransom offers few guarantees.
It is worth watching whether more named victims come forward, whether the Sleepless Threat rebrand appears, and whether low-level agents in the US face charges. Recent cases, such as a Qilin suspect arrested in Japan, indicate that the group's worries about travel and extradition may not be unfounded.
