Ransomware Intelligence

blackshrantac Ransomware Group

Ransomware group profile

37Victims
United StatesSource country
60Impact score

Description

Blackshrantac is a financially motivated ransomware group that emerged in September 2025, known for its disciplined and sophisticated tactics. The group primarily employs double extortion strategies to maximize pressure on victims, utilizing legitimate commercial tools for intrusion and persistence while focusing on evading detection.

Key insights

  • Gains initial access by exploiting CVE-2024-3400 in Palo Alto Networks PAN-OS devices and through phishing emails.
  • Utilizes a primary encryptor binary for execution without administrative privileges and leverages legitimate tools for remote access.
  • Employs a double extortion model, exfiltrating sensitive data before encrypting files and demanding ransom.
  • Disables backups and security controls to enhance the effectiveness of their attacks.
  • Uses a leak site on the Tor network to publish victim information and apply pressure through public disclosure threats.

Threat Level & Status Breakdown

For blackshrantac · Based on incidents in selected period

Status Breakdown

Claimed100.0%37
First seenSep 2025
Last seenJan 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedAug 7, 2026

Recent activity

Monthly attack count for blackshrantac in the selected period

37Total attacks
15peak in Oct
7.4avg / month
↓ 2 vs first month
SepOctNovDecJan0481216

Intelligence

IOCs, YARA/Sigma rules, and related families for blackshrantac

  1. b2ykcy2gcug4gnccm6hnrb5xapnresmyjjqgvhafaypppwgo4feixwyd.onion
  2. jvkpexgkuaw5toiph7fbgucycvnafaqmfvakymfh5pdxepvahw3xryqd.onion
View full IOC feed2 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for blackshrantac

Other

T1486

T1486

T1490

T1490

T1078

T1078

T1574

T1574

T1021

T1021

T1562

T1562

T1059

T1059

T1547

T1547

T1040

T1040

T1105

T1105

T1485

T1485