Luna Moth Expands Attack Arsenal with Deceptive Helpdesk Domains in Precision Phishing Campaigns
A newly exposed phishing campaign attributed to the Luna Moth threat group is targeting legal and financial entities in the U.S., using a web of misleading domains crafted to appear as trusted IT support portals.
Threat analysts at EclecticIQ, in collaboration with Silent Push, have traced a calculated domain registration strategy that allows security teams to stay ahead of evolving threat infrastructure. This proactive mapping has uncovered a sweeping digital footprint.
Active since at least March 2025, Luna Moth—also known as Silent Ransom Group, UNC3753, or Storm-0252—has ramped up activity, registering more than three dozen deceptive domains via GoDaddy. New data indicates that number may now surpass 50, each engineered to mirror internal support services with URLs like [brand]-helpdesk.com.
According to EclecticIQ’s latest threat briefing, the group is likely executing high-frequency callback phishing attacks tailored for U.S.-based financial and legal sectors—using familiarity and urgency as their primary weapons.

Luna Moth Adopts AI-Driven Social Engineering in Stealthy Callback Campaigns
The Luna Moth group is reshaping the phishing landscape with an unconventional approach that ditches the usual playbook of suspicious links and infected attachments. Instead, attackers initiate contact through innocuous-looking emails that nudge recipients to place a phone call—kickstarting a manipulative process known as Telephone-Oriented Attack Delivery (TOAD).
Hijacking Trust Through Live Chat Fakery
What sets this campaign apart is its use of live AI-powered deception. The attackers have co-opted Reamaze—a legitimate customer service platform owned by GoDaddy—to host interactive chatbot interfaces. Victims are greeted with what appears to be a helpful IT support agent, but the chatbot is engineered to lead them step-by-step into installing trusted remote access tools like AnyDesk, TeamViewer, and ScreenConnect.
By leveraging these widely-used applications, Luna Moth bypasses traditional malware defenses, gaining full control of target systems without triggering most endpoint protections.
Infrastructure Tracking: A Blueprint for Early Detection
Security teams at Silent Push, expanding on threat intelligence from EclecticIQ, have reverse-engineered Luna Moth’s infrastructure-building playbook. Their research highlights a repeatable set of characteristics that can be used to proactively detect and monitor the group’s evolving domain footprint:
- Domain naming follows a helpdesk-mimicking pattern, using regex:
^[a-z]{1,}-help(desk)?\.com$ - Domains are consistently registered through GoDaddy
- Hosted on domaincontrol.com nameservers
- Registered after March 2025, coinciding with the latest surge in activity
This methodology offers defenders a predictive edge—enabling threat hunters to identify malicious infrastructure before it’s fully operational.

Legal Sector in the Crosshairs: Luna Moth’s Domain Spoofing Tactics Exposed
A forensic sweep using targeted domain discovery methods has surfaced a network of roughly 50 impersonation domains engineered to exploit the reputational trust of top-tier law firms. Among the confirmed decoys are convincing replicas like duanemorris-helpdesk.com, perkinscoie-helpdesk.com, and millermartin-helpdesk.com—all crafted to appear as internal IT portals.
This wave of domain-based social engineering underscores Luna Moth’s precision targeting strategy. Analysis of impacted sectors reveals a sharp concentration: law firms make up over 40% of identified victims, highlighting a deliberate focus on organizations that handle confidential client data and sensitive legal proceedings.
Trailing behind are firms in financial services (23.61%) and accounting (13.89%), indicating a broader campaign aimed at high-value, document-rich industries where access can yield significant returns.
This pattern suggests not just opportunism, but a strategic prioritization of sectors with both high trust thresholds and lucrative access potential.

Data Theft Without Malware: Luna Moth Monetizes Trust with Clean Tool Abuse
Once inside a compromised environment, Luna Moth actors quietly extract confidential files using trusted software like WinSCP and Rclone—avoiding typical malware signatures that most security tools rely on. The stolen data is then leveraged for extortion, with ransom demands ranging from $1 million to $8 million, all negotiated through the group’s leak platform: business-data-leaks[.]com.
This playbook reflects a high-stakes targeting model. “Luna Moth is clearly prioritizing sectors where data sensitivity intersects with reputational risk—especially law, finance, and insurance,” notes EclecticIQ. These industries often lack room for negotiation, making them prime candidates for fast, high-value payouts.
Defense Through Awareness and Proactive Detection
To counter this evolving threat, security leaders should prioritize:
- Strengthening email filtering and impersonation detection
- Training staff to recognize callback phishing lures disguised as IT helpdesk communications
- Deploying threat rules that flag installation or unusual use of remote management tools like AnyDesk or TeamViewer
- Continuously scanning for typosquatted domains using the domain fingerprinting methods highlighted in current threat intelligence research
As attackers continue to abuse legitimate infrastructure and software, defenders must shift focus from malware signatures to behavioral anomalies and infrastructure mimicry.




