Ransomware & Extortion · Ransomware

Black Shrantac Turns Perimeter Flaws Into Quiet Extortion

Black Shrantac is not trying to be noisy. It is using a perimeter flaw to get in, then leaning on legitimate admin tools so the intrusion looks like normal activity. That makes the usual malware-focused detection playbook miss the point: the danger is sparse telemetry and a faster path to double extortion.

Marlink says the group has been active since September 2025 and has used CVE-2024-3400 for initial access, with victims across manufacturing and critical infrastructure among other sectors. The report says Black Shrantac favors trusted tools and existing infrastructure over custom malware, which reduces visible indicators and complicates attribution.

The forward risk is persistence with little forensic residue. Once access is gained through exposed perimeter systems, defenders may be left with fewer artifacts to prove what was touched before data theft and extortion begin.

1 source · Apr 15

CVE-2024-3400

NVD KEV

Known exploited · CISA KEV

CVSS 10 CRITICAL: a command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto… Known ransomware campaign use. EPSS 100% (100th percentile).

CISA federal remediation date Apr 19 · date passed

Timeline

Sources

Part of the PlainSec briefing for 2026-05-03

Every edition of this story: Black Shrantac Turns Perimeter Flaws Into Quiet Extortion