Back to Insights Phishing

How a phishing attack combined with phone calls works – the Luna Moth attack

General Description of Social Engineering Attacks and System Access

The FBI has issued a warning regarding sophisticated cyberattacks by the Luna Moth group, also known as Chatty Spider and Silent Ransom Group. Over the past two years, the group has been targeting law firms using voice phishing (vishing) and email fraud. They employ clever techniques such as “callback phishing” to gain remote access to systems, exfiltrate sensitive information, and extort victims. The attacks begin with emails instructing victims to call phone numbers provided in innocent-looking phishing messages related to invoices and subscription payments. During the phone call, victims are sent a link to download software that grants the attackers access to the system. Subsequently, they steal personal information and threaten to publish the stolen data unless a ransom is paid.

Transition to New Methods: IT Department Impersonation Attacks

Since March 2025, Luna Moth has shifted its operational methods, now directly contacting employees within organizations first. Attackers pose as IT department staff and carry out remote access attacks. They lure employees into joining remote access sessions under the guise of assisting with software installation, which ultimately provides the attackers with unauthorized access to the firm’s systems. To execute these attacks, Luna Moth utilizes well-known remote management technologies such as Zoho, Assist, AnyDesk, and WinSCP. The use of legitimate tools allows the attacks to remain undetected by conventional security tools, making discovery difficult.

Recommendations from IPV Security Information Security Experts

  • Implementation of Multi-Factor Authentication: It is recommended that all employees enable Multi-Factor Authentication (MFA/2FA) on all personal and business accounts to ensure no unauthorized access to organizational systems.
  • Ongoing Employee Training: Ensure employees are aware of threats such as voice and email phishing, and provide regular training on identifying suspicious communications.
  • Regular Review of Remote Access Tools: Conduct ongoing reviews of the tools and configurations used for remote access to ensure there are no suspicious or unauthorized connections.
  • Monitoring Outbound Connections: Organizations should monitor outbound connections from their systems, particularly those using tools like WinSCP and Rclone, to ensure they are not communicating with suspicious IP addresses.
  • Enhanced Protection for Critical Systems: Ensure high-level protection systems are active on computers and servers containing sensitive information, and avoid granting administrative privileges to users who do not require them.
  • Identifying Suspicious Emails: It is crucial to learn how to identify emails instructing users to call an external phone number or download software, especially when messages appear legitimate but demand urgent action.

In summary, the Luna Moth group poses a severe threat to law firms and other organizations through clever phishing techniques that exploit remote access tools. To prevent these attacks, comprehensive security measures must be maintained, and vigilance is required for any suspicious contact, particularly via telephone and email.

For further information: https://thehackernews.com/2025/05/hackers-are-calling-your-office-fbi.html

Continue the Conversation

Facing a cybersecurity challenge? Let's talk about how a managed program can strengthen your resilience.

Start a conversation