blackshrantac Ransomware Group
Ransomware group profile
Description
Blackshrantac is a financially motivated ransomware group that emerged in September 2025, known for its disciplined and sophisticated tactics. The group primarily employs double extortion strategies to maximize pressure on victims, utilizing legitimate commercial tools for intrusion and persistence while focusing on evading detection.
Key insights
- •Gains initial access by exploiting CVE-2024-3400 in Palo Alto Networks PAN-OS devices and through phishing emails.
- •Utilizes a primary encryptor binary for execution without administrative privileges and leverages legitimate tools for remote access.
- •Employs a double extortion model, exfiltrating sensitive data before encrypting files and demanding ransom.
- •Disables backups and security controls to enhance the effectiveness of their attacks.
- •Uses a leak site on the Tor network to publish victim information and apply pressure through public disclosure threats.
Threat Level & Status Breakdown
For blackshrantac · Based on incidents in selected period
Status Breakdown
Recent activity
Monthly attack count for blackshrantac in the selected period
Intelligence
IOCs, YARA/Sigma rules, and related families for blackshrantac
- b2ykcy2gcug4gnccm6hnrb5xapnresmyjjqgvhafaypppwgo4feixwyd.onion
- jvkpexgkuaw5toiph7fbgucycvnafaqmfvakymfh5pdxepvahw3xryqd.onion
TTPs & Attack Vectors
Tools, initial access, and MITRE ATT&CK techniques for blackshrantac
T1486
T1486
T1490
T1490
T1078
T1078
T1574
T1574
T1021
T1021
T1562
T1562
T1059
T1059
T1547
T1547
T1040
T1040
T1105
T1105
T1485
T1485
Affected countries(27)
Countries where this group has been reported to target or leak victims.