Silent Ransom Group Hits US Law Firms in Escalating Extortion Attacks
2026-06-09T02:51:40Z•31ca88cf696bb1a4dd4b3c8fe2b5801e5e28471596a753977adc91918582b2de
AI-wormsCheck PointEDR-evasionGlobalProtectHadesIronWormKali365','ClickFix','DriveSurge','credential-theft','RAT','BTMOBNPMPAN-OSPalo AltoPyPIQilinShai-HuludSilent Ransom GroupVPNagentic-AIauth-bypassextortionin-person-intrusionphishingransomwaresocial-engineeringsupply-chainvishingzero-day
What happened
DarkReading batch (early June 2026) highlights multiple active, high-impact threats: a financially motivated extortion campaign (Silent Ransom Group) targeting U.S. law firms using vishing, IT impersonation and in-person intrusions; at least one critical VPN zero-day in Check Point appliances under active exploitation (linked to a Qilin ransomware affiliate); and an actively exploited Palo Alto PAN‑OS GlobalProtect authentication bypass. Software supply‑chain attacks continue (Hades campaign on PyPI, IronWorm on NPM, Shai‑Hulud variants) alongside broad malware/RAT activity (BTMOB, Xeno) and T
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 31ca88cf696bb1a4dd4b3c8fe2b5801e5e28471596a753977adc91918582b2de
- Enrichment time
- 2026-06-09T02:51:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.