Legal

The attack your antivirus was never built to see

A crew researchers call Silent Ransom Group has been calling law firms and pretending to be their IT department.

1 min readOriginally posted on LinkedIn

A crew researchers call Silent Ransom Group has been calling law firms and pretending to be their IT department.

The playbook is simple. An invoice-themed email lands first. Then the phone rings, and a helpful voice walks someone at the firm through joining a remote support session and installing a remote access tool — AnyDesk, Zoho Assist, something ordinary. From there they go looking for contracts, tax records and deal files, and quietly copy them out of the building.

Here's the part that matters: there is no malware anywhere in that chain. Every tool they use is legitimate software your own IT provider might use on a Tuesday.

That's why antivirus doesn't stop it. Antivirus asks one question — is this file known to be bad? AnyDesk isn't bad. It's a bouncer checking IDs against a banned list, and this guest is on the list.

EDR, endpoint detection and response, asks a different question: does this behavior make sense? Someone installed a remote access tool at 6pm and immediately started bulk-copying the client folder. No single step is criminal. The sequence is.

For a 20-attorney firm the cost isn't abstract. It's days of lost billable hours and a phone call to your biggest client explaining what walked out the door.

Worth a look before your next cyber renewal.

ShareLinkedInEmail

Want the next one in your inbox?

One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.

Subscribe via email

All editions