Silent Ransom Group (SRG): Switching To DNS Fast Flux Infrastructure


Silent Ransom Group (SRG): Switching To DNS Fast Flux Infrastructure

Pierluigi Paganini
June 05, 2026

Researchers exposed the Silent Ransom Group ‘s Fast Flux infrastructure as the FBI warns of ongoing attacks targeting U.S. law firms and businesses.

Resecurity uncovered the Silent Ransom Group (SRG)’s Fast Flux network infrastructure and shares available intelligence with the cybersecurity community to disrupt their malicious activities and enable ISP/DNS providers to counter this threat.

“Resecurity is the first to uncover the SRG’s Fast Flux network infrastructure and is sharing this intelligence with the cybersecurity community to disrupt their malicious activities and enable ISP/DNS providers to counter this threat.” reads the report published by Resecurity.

The Silent Ransom Group, also known as Luna Moth, Chatty Spider, and UNC3753, is a cyber extortion group active since 2022 that focuses on stealing sensitive data and extorting victims rather than encrypting files. The group primarily targets organizations in sectors such as legal services, healthcare, hospitality, finance, and insurance.

The experts also outlined the use of X-CSRF (Cross-Site Request Forgery) token to prevent indexing of their Data Leak Site (DLS) – a unique, secret, and unpredictable string that a server-side application generates and assigns to a user’s session.

The Federal Bureau of Investigation (FBI) recently issued an advisory about the SRG, which is actively targeting U.S.-based law firms and other industries through social engineering and in-person attacks.

The Fast Flux nodes were identified in Latin America (Brazil, Mexico, Argentina, Ecuador, Colombia, Bolivia, Costa Rica, Peru, Panama), Eastern Europe (Bulgaria, Croatia, North Macedonia), Central Asia (Uzbekistan, Kyrgyzstan), Middle East/Africa (Egypt, Saudi Arabia, Tunisia), East Asia (South Korea), and Caribbean (Jamaica, Dominican Republic). The bots are likely infected via vulnerable IoTs and Customer Premises Equipment (CPE) — such as routers, modems, and gateways. New underground projects have been identified that could be linked to the SRG (by profile, targets and the mapped infrastructure), including Spy Corporate, which emerged in May 2026. Fast Flux provides the SRG with resilient infrastructure to extort top AmLaw 100 firms and other victims.

Last year, the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), Canadian Centre for Cyber Security (CCCS), and New Zealand National Cyber Security Centre (NCSC-NZ) released a joint advisory “Fast Flux: A National Security Threat,” highlighting the importance of collaboration between the private and public sectors.

The SRG’s botnet appears to rely on compromised IoT devices and customer equipment such as routers, modems, and gateways. Researchers also found links to other underground projects, including Spy Corporate, launched in May 2026. The group uses Fast Flux infrastructure to make its operations more resilient while targeting major law firms for extortion.

“Based on further analysis, other underground projects have been identified that could be linked to the SRG, including Spy Corporate, which emerged in May 2026. Fast Flux provides the SRG with resilient infrastructure to extort top AmLaw 100 firms.” concludes the report, which includes technical details about the Fast Flux Infrastructure.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Silent Ransom Group)







Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


Plex’s Remote Watch Pass is getting a 50% price hike starting June 1, 2026. Plex introduced the Remote Watch Pass in April 2025 as a cheaper alternative to the Plex Pass. Remote Watch Pass allows users to remotely stream from any Plex Media Server that a user has access to.

Remote Watch Pass essentially gives a user access to remote streaming, but that’s about it. It’s ideal for those who only want to use Plex as a viewer who is accessing someone else’s Plex Media Server. Core features and benefits of a Plex Server are locked behind the Plex Pass subscription instead.

Currently, Remote Watch Pass is available for $1.99 per month, and its annual plan is for $19.99. This has been the introductory price since the April launch last year. It’s now getting a price bump, and it’s a considerable increase.

A Reddit user received the price increase information via email and shared it with other users. The email said, “We hope you’re enjoying your Remote Watch Pass and the ability to stream personal media wherever you go. We wanted to let you know that your Remote Watch Pass introductory pricing is ending on June 1st, 2026. Beginning on June 1st, 2026, renewals for your subscription will be at the normal subscription price.”


A phone with the Plex logo and a laptop beside it with the Plex home screen.


Plex Pass Lifetime Memberships Double in Price Next Month, so Sign Up Now

Plex Pass will experience a major price hike on April 29th. Grab a lifetime membership today to avoid the price hike.

Plex Remote Watch Pass will increase from $1.99/month to $2.99/month, and its annual plan will increase from $19.99 to $29.99/year. Given that users have enjoyed the introductory price for over a year, the price increase was expected to come at some point.

Users who own a server and have a Plex Pass can share their benefits and let other users stream from their server for free. That’s another reason why Plex Pass continues to be the popular choice for Plex users. You can also get a Plex Pass lifetime subscription, but there’s no such option for Remote Watch Pass yet.

Sharing thoughts in the same Reddit post, there’s a majority of Plex users who feel that the Plex Pass lifetime pass, which is available for $249.99, is an increasingly attractive option. “Best thing I ever did was buy the lifetime pass,” shared one user.

However, for those who only want the Plex experience as a viewer on someone else’s server, the Remote Watch Pass is the cheaper option when compared to the standard pricing of a Plex Pass subscription, which is available for $6.99 per month, or $69.99 for a year.

Source: Reddit

Compatibility

Windows, Linux, macOS, Android, iOS, and various other devices

Free Trial Period

Free account available




Source link