Beware of scammers impersonating Crystal Intelligence

Investigations | October 6, 2026

Inside the Silent Ransom Group leak: how ransoms were laundered

By Nicholas Smart
Chief Intelligence Officer, Crystal

Share via:

A ransomware group that never encrypts a file says it was paid $207M in under six months. Its own chat logs, published on a ransomware leak site, show how that money was meant to disappear: single-use wallets, instant exchangers paying out to Russian bank cards, a Bitcoin-to-Zelle desk, and property bought with a cover story for the bank.

Crystal analyzed the export, which holds 5,692 messages from August 2025 to September 2026, mostly in Russian, and traced the wallet addresses in it. The headline figures can’t be verified. The blockchain does confirm that real money moved when the chat says it did, and it shows where the group’s own rules broke down. Those are the points where compliance teams and investigators can act.

Key points

  • The chat points to Silent Ransom Group (SRG), also tracked as Luna Moth. SRG is a Conti offshoot that extorts law firms through phone-based social engineering and, more recently, in-person office visits.
  • The group’s internal deal board claims about $207M paid by 27 firms between April 3 and September 24, 2026. On-chain evidence supports the scale but not the exact figures.
  • Payouts followed strict wallet rules designed to defeat tracing. The operators didn’t always follow them.
  • Cash-out ran through instant exchangers, a Moscow cash courier, a Bitcoin-to-Zelle desk, and a coin-mixing wallet when funds were flagged.
  • Many smaller payments went straight to regulated exchanges, where accounts are tied to verified identities. This is the network’s weakest point.

Who is Silent Ransom Group?

SRG, also tracked as Luna Moth, Chatty Spider, UNC3753 and Storm-0252, emerged in 2022 after the Conti ransomware group shut down. Its operators previously ran BazarCall, a callback phishing campaign that gave the Ryuk and Conti gangs access to victim networks.

SRG doesn’t use ransomware. It sends staff fake invoices, or calls them posing as “IT support,” and talks them into granting remote access. It then steals data and threatens to publish it. Since 2023 it has focused on US law firms, which hold privileged client data and face heavy reputational pressure to pay.

In May 2026, the FBI warned that the group had also started sending people into victims’ offices with fake IDs [link to FBI FLASH alert].

The group operates from Russia, and its tactics and targets match the public assessment of SRG as a Russia-based Conti successor.

How much did the group really make?

The group tracks each victim through a series of stages. The final stage is “GOLD,” meaning paid. Adding up the 27 firms marked GOLD gives about $207M between April 3 and September 24, 2026. Its leaders also made running claims, including $43.95M “received this season” on May 4, a “half-a-billion-dollar plan for the season” on September 2, and “$51M made, plan $350M” on September 21.

These are the group’s own figures, and criminals exaggerate. What the blockchain can show is whether money moved when the chat says it did.

Date

Claim in the chat

What the blockchain shows

June 8, 2026

$17.5M

The recruiter’s wallet receives 4.727 BTC (about $300K) from a 5.54 BTC source

May 4, 2026

$19M

A wallet named in the chat receives exactly 4.75505224 BTC at 21:01 that day

April 3, 2026

$275K

A share payment of 0.0448 BTC (about $3,000) is confirmed

February 20, 2026

$1M settlement

A source wallet receives 13.23 BTC (about $898K) that evening and pays 0.735 BTC to the recruiter

The confirmed amounts are the operators’ share of each payment, not the full ransom. They back up the timing, not the headline figures.

Every payout we traced followed the same pattern. A single-use wallet sends a small amount to the recipient and the rest to a fresh address. The wallets named in the chat received about 37 BTC in total, worth around $3M. About $2.7M of that was the operators’ personal cut. Small amounts went to agents, forged-document suppliers and cash-out services. None of these wallets ever held a full ransom.

The bigger picture appears one step upstream. Four of the largest payouts came from wallets holding 8, 89, 22, and 7 BTC, 126 BTC in total. Following one chain further back leads to a collection wallet. It received 344 BTC (about $27M) in six weeks during April and May 2026, and about 2,675 BTC (around $200M) over its lifetime.

No single wallet can be tied to a specific victim payment, so individual figures remain unproven. The flows are consistent with a group moving multi-million-dollar sums, as it claims.

How did the group try to hide the money?

On April 3, 2026, the operations lead set out rules for receiving payouts, and he repeated them often:

  • Use a fresh address for every payout. Reject reused or “unclean” wallets.
  • Keep one victim per wallet. Never mix coins from different victims.
  • Never consolidate payouts.
  • Ask cash-out providers for several unlinked deposit addresses.
  • Keep the cash-out service separate from the receiving wallet, and delay cashing out.

The group also screened its own coins. In one message, a $4,000 payout was described as “93% dirty,” which suggests the recruiter was running a risk tool himself. When an exchanger bounced a payment over an “AML problem,” the refund went to a Wasabi Wallet address. Wasabi uses CoinJoin, a method that mixes coins from many users to break the trail.

The rules didn’t always hold. On April 22, 2026, the recruiter spent two separate payouts in a single transaction, which linked them on-chain. That one mistake connects wallets the rules were meant to keep apart. For investigators, it’s a reminder that tracing often succeeds because of human error.

Where did the money go?

The chat describes four main routes from Bitcoin to spendable money.

Instant exchangers to Russian bank cards. The operators sent BTC or USDT to an exchanger’s address and received rubles on a Russian bank card within minutes, often at Tinkoff (now T-Bank). Quoted rates expired quickly, and one message mentions a 58-minute window. Crystal rates one deposit address used for this route as high risk, with exposure to unlicensed exchanges and dark-web markets.

A Moscow cash courier. For larger sums and physical cash, the group used an over-the-counter (OTC) broker they called “Zhenya,” with a minimum of about $10,000. The operators suspected him of skimming on the exchange rate.

A Bitcoin-to-Zelle desk. To pay people in the US, the operations lead shared a Telegram contact, @SAFUexchange, describing them as “the people we swap bitcoin to Zelle with.” Crystal’s data lists the same Telegram handle for an unlicensed exchange based in Georgia, sanctions-flagged and rated maximum risk. It advertises direct Bitcoin-to-Zelle conversion alongside payouts to Russian banks and other services.

Regulated exchanges. Many smaller payments, such as wages to field agents and fees to document forgers, went straight to deposit addresses at mainstream exchanges. These platforms verify their customers’ identities, so each address is tied to a real person. This is the network’s weakest point, and the most direct route for law enforcement to identify the people behind the handles.

How did the group get past source-of-funds checks?

Converting crypto to rubles solved only half the problem. The other half was spending the money without a bank asking questions.

The recruiter bought property in Russia through a power of attorney. When the bank asked where the money came from, he answered “savings.” The operations lead advised a more careful approach:

  • Buy in person, not remotely.
  • Use a mortgage, so the purchase looks income-backed.
  • Bank through a premium banking tier, where private-banking managers “solve problems” for valuable clients.
  • If pressed, call the money an inheritance or a gift, or produce a fake loan agreement. “It works.”

Another operator suggested buying new-build property paid through developer escrow accounts. The recruiter also discussed buying a Porsche 911 with his share.

For bank compliance teams, this is a practical list of cover stories to test when a high-value client’s source of funds doesn’t match their profile.

Why this is more than a ransomware story

The chat shows a group that works more like an organized crime network than a typical ransomware crew. That changes the risk for anyone handling its money. Funds linked to it may carry money-mule, illicit-goods and sanctions exposure, not just ransomware exposure. The operators also discussed kidnapping employees and blackmailing targets, though there is no evidence any of these plans were carried out.

Recruited field agents. The group posted Russian-language ads for “nightclub promoters” in Miami, Orlando, and New York, paying $300 or more a night. Respondents were steered into the field-agent roles used to enter law firm offices. For banks and VASPs, this looks like money-mule recruitment: ordinary customers receiving small, regular payments in crypto, through Zelle or at exchanges, for vague work.

Weapons paid for in crypto. The operators arranged to buy weapons from a Ukraine-based dealer, and on May 30, 2026, posted a wallet to pay for them. Ransom proceeds moving toward weapons should raise the priority of a suspicious activity report and of any referral to law enforcement.

Paying insiders. Operators discussed offering up to $100,000 to insiders at US defense-sector targets in exchange for data. A large crypto-funded payment to an employee with access to sensitive information is a red flag in its own right.

A possible state buyer. In one discussion about stealing defense data, an operator said “the money will come from the RF Ministry of Defense.” This shows intent, not a confirmed relationship. It still matters for sanctions: if proceeds may reach a state-linked buyer, banks and insurers that help a victim pay a ransom face sanctions exposure. The group itself noted that a defense contractor paying it could be prosecuted as a terrorism financier.

What this means for compliance teams

VASPs and exchanges

  • Small, regular deposits from single-use wallets that sit one step from large, unattributed collection wallets
  • Funds that passed through CoinJoin shortly after a bounced or refunded transaction
  • Customer exposure to the cash-out routes above, which may indicate field agents, couriers, or document forgers

Banks and financial institutions

  • Property purchases backed by “savings,” an inheritance, a gift, or a private loan that doesn’t match the client’s profile
  • Pressure to route high-value payments through private-banking channels with lighter checks
  • Incoming Zelle or card payments linked to crypto-to-cash desks

Law enforcement

  • Deposit addresses at regulated exchanges are the most direct route to identifying people in the network.
  • Operator mistakes, such as spending two payouts together, link wallets the group meant to keep apart.

FAQ

What is Silent Ransom Group? A data-extortion group, also tracked as Luna Moth, that emerged after Conti shut down in 2022. It tricks staff into granting remote access, steals data, and threatens to publish it. It doesn’t encrypt files.

Did Silent Ransom Group really make $207M? That figure is the group’s own internal claim. Blockchain analysis confirms that large sums moved in line with the chat, including a collection wallet that received about 2,675 BTC over its lifetime. It can’t confirm individual ransom amounts.

Why are law firms targeted? They hold privileged client data and would suffer serious reputational damage from a leak, which puts pressure on them to pay.

How did the group cash out? Through instant exchangers paying out to Russian bank cards, a Moscow cash courier, and a Bitcoin-to-Zelle desk. Smaller payments went to regulated exchanges.

Is Silent Ransom Group linked to the Russian state? The chat shows the group operates from Russia and discussed selling defense data to the Russian Ministry of Defense. There’s no evidence of a confirmed relationship in which the state directs its work.

How can compliance teams spot related funds? Look for deposits from single-use wallets linked to large upstream wallets, funds that recently passed through CoinJoin, and source-of-funds explanations that don’t match a client’s profile.

Conclusion

Silent Ransom Group’s headline numbers are its own. The blockchain confirms the method and the scale: strict payout rules, fast conversion to rubles and Zelle, and property bought with a cover story. It also shows where that discipline failed, from a recruiter linking his own wallets to contractors paid at regulated exchanges.

To find out more about this story, book your call with us today. 

Summarize with AI
On this page
Subscribe to our newsletter

Thought Leadership | October 6, 2026

New Brazil PSAV compliance rules: from policy to proof

Brazil's PSAV rules demand proof that controls work. What it means for governance, travel rule readiness, and vendors before the October 29 deadline.

Stablecoin | October 6, 2026

OUSD's first week on-chain: $666M staged across the issuer and partner network

Where Open USD's first $717M went: placed with partners, held at Coinbase, and slowly started trading. A wallet-level read of OUSD's first week.

Thought Leadership | October 1, 2026

Operating in New York: key facts for crypto compliance teams

Unlicensed crypto activity persists alongside New York regulation. Experts discuss what compliance teams should do.