Ransomware Intelligence

blackshrantac

Ransomware group profile

44Victims
United StatesSource country
50Impact score

Description

Blackshrantac is a financially motivated ransomware group that emerged in September 2025, known for its disciplined and sophisticated tactics. The group primarily employs double extortion strategies to maximize pressure on victims, utilizing legitimate commercial tools for intrusion and persistence while focusing on evading detection.

Key insights

  • Gains initial access by exploiting CVE-2024-3400 in Palo Alto Networks PAN-OS devices and through phishing emails.
  • Utilizes a primary encryptor binary for execution without administrative privileges and leverages legitimate tools for remote access.
  • Employs a double extortion model, exfiltrating sensitive data before encrypting files and demanding ransom.
  • Disables backups and security controls to enhance the effectiveness of their attacks.
  • Uses a leak site on the Tor network to publish victim information and apply pressure through public disclosure threats.

Threat Level & Status Breakdown

For blackshrantac · Based on incidents in selected period

1.9threat level
Aggressiveness5/ 10
Lethality0/ 10
Criticality0.4/ 10

Status Breakdown

Claimed100.0%44
First seenSep 2025
Last seenJan 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 2, 2026

Recent activity

Monthly attack count for blackshrantac in the selected period

44Total attacks
16peak in Oct
8.8avg / month
↓ 8 vs first month
SepOctNovDecJan0481216

Intelligence

IOCs, YARA/Sigma rules, and related families for blackshrantac

  1. b5f90df776e6f57a7fec03f9e325ccf9debe4ddbcc8c385f0bb3edd91ef71927
  2. e1201ab8925e3a89bf842ecaab68c3faba5d85b113b42fb05aae687d9dbfb251
  3. 7ffacc87f6b1701308fbfcae45c335aadb675c66cc859e998103b090034f6e7c
View full IOC feed3 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for blackshrantac

Other

T1486

T1486

T1490

T1490

T1078

T1078

T1574

T1574

T1021

T1021

T1562

T1562

T1059

T1059

T1547

T1547

T1040

T1040

T1105

T1105

T1485

T1485

Victims(44)

CompanyDomainCountryIndustryStatusDiscovered
PKT QSpktqs.comGB United KingdomProfessional Services
Claimed
4 months ago
National Water Authorityana.gob.pePE PeruGovernment & Defense
Claimed
5 months ago
SCHNEIDER PROTOTYPING INDIA PVT. LTDsi-smart.netIN IndiaManufacturing
Claimed
5 months ago
Agrícola Cerro Prietoagricolacerroprieto.pePE PeruOther
Claimed
5 months ago
Netstar Australia PTY Ltdnetstar.com.auAU AustraliaTechnology
Claimed
6 months ago
demilac, Incdemilac.com.trTR TurkeyRetail & E-Commerce
Claimed
6 months ago
VFM Systems & Services (P) Ltdvfmsystems.comIN IndiaTechnology
Claimed
6 months ago
Rasen Insaat Ve Yatirim Ticaret A.S.rasen.com.trTR TurkeyOther
Claimed
6 months ago
Badan Pengelola Keuangan Hajibpkh.go.idID IndonesiaFinancial Services
Claimed
6 months ago
HexaCream Dental Laboratoryhexadentallab.comTH ThailandHealthcare
Claimed
4 months ago
Superintendencia Nacional de Fiscalización Laboralsunafil.gob.pePE PeruGovernment & Defense
Claimed
6 months ago
libertyshoes, Inclibertyfootfashion.comIN IndiaRetail & E-Commerce
Claimed
7 months ago
Newgen Digitalworknewgen.coIN IndiaTechnology
Claimed
7 months ago
MultistateTax Incmultistatetax.netUS United StatesFinancial Services
Claimed
7 months ago
Carvimsacarvimsa.com.pePE PeruManufacturing
Claimed
7 months ago
simsekas, Incsimsekas.com.trTR TurkeyRetail & E-Commerce
Claimed
7 months ago
M&BM, Incmdm-bg.comBG BulgariaManufacturing
Claimed
7 months ago
CCI Tax Pros, Incccitaxpros.comUS United StatesFinancial Services
Claimed
7 months ago
The Matlusky Firm LLCmatluskylaw.comUS United StatesProfessional Services
Claimed
7 months ago
CyPark Resources Berhadcypark.comMY MalaysiaEnergy & Utilities
Claimed
7 months ago

Page 1 of 3