Threat actor · all actors
Luna MothMISP-f5022a01 criminal
aka Luna Moth, Silent Ransom, TG2729
Last updated: 2026-08-20
About this actor
Luna Moth conducts high-tempo callback phishing campaigns targeting legal and financial organizations in the U.S., using social engineering to lure victims into calling fake helpdesk numbers. Attackers impersonate IT staff to install legitimate RMM tools, enabling direct access to victim systems for data exfiltration. The group demands ransoms between $1 million and $8 million, threatening to leak stolen data if payments are not made. Their operations reflect a shift from traditional ransomware tactics to data breach extortion, leveraging trusted systems to evade detection.
How we know this
- Data origin
- MISP threat-actor galaxy Imported from the open-source MISP threat-actor galaxy.
- Techniques
- Curated — 1 ATT&CK technique on file.
- Named victims
- None on file.
Thin data: Only 1 ATT&CK technique mapped — a thin behavioural profile; absence is not evidence of a narrow toolkit.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
Co-occurring actors
None.
Similar actors
Similar TTPs
- BlackBasta 1.00
- UNC6040 0.20
- ShinyHunters 0.17
- scattered lapsus$ hunters 0.17
- C0027 0.02
Same category
- LAPSUS$ 1.00
- Akira 1.00
- INC Ransom 1.00
- Play 1.00
- BlackByte 1.00