It starts, like many scams, with a phone call. The threat actor attempts to convince the victim to install a remote desktop management tool, which would grant the hacker access to company systems. But if the victim doesn’t fall for it, this particular hacking group isn’t giving up.
According to the FBI, the hacking group, which goes by the name Silent Ransom Group (SRG), will turn up at an office in person to steal data and install malware. They pose as IT support personnel and come armed with flash drives and external disks, which they then connect to an office computer under the guise of fixing a technical issue. Instead, they download company data and install malware, then leave and contact the victim to extort them at a later date. SRG also has a website where they publish the names of victims who don’t pay up, as an attempt to name-and-shame them into compliance.