Cyber Resilience

Threat actor · all actors

Luna MothMISP-f5022a01 criminal

aka Luna Moth, Silent Ransom, TG2729

Last updated: 2026-08-20

0attributed CVEs
1ATT&CK techniques
0.0IDF score (tooling uniqueness)
0exclusive CVEs
years active

About this actor

Luna Moth conducts high-tempo callback phishing campaigns targeting legal and financial organizations in the U.S., using social engineering to lure victims into calling fake helpdesk numbers. Attackers impersonate IT staff to install legitimate RMM tools, enabling direct access to victim systems for data exfiltration. The group demands ransoms between $1 million and $8 million, threatening to leak stolen data if payments are not made. Their operations reflect a shift from traditional ransomware tactics to data breach extortion, leveraging trusted systems to evade detection.

How we know this

Data origin
MISP threat-actor galaxy Imported from the open-source MISP threat-actor galaxy.
Techniques
Curated — 1 ATT&CK technique on file.
Named victims
None on file.

Thin data: Only 1 ATT&CK technique mapped — a thin behavioural profile; absence is not evidence of a narrow toolkit.

See how actor data is built for the full pipeline.

Activity timeline

No activity events recorded.

Profile

CVERiskCVSSEPSSPublishedProducts
No attributed CVEs.

Co-occurring actors

None.

Similar actors

Same category