Ransomware ed estorsione · Ransomware

Black Shrantac Turns Perimeter Flaws Into Quiet Extortion

Black Shrantac is not trying to be noisy. It is using a perimeter flaw to get in, then leaning on legitimate admin tools so the intrusion looks like normal activity. That makes the usual malware-focused detection playbook miss the point: the danger is sparse telemetry and a faster path to double extortion.

Marlink says the group has been active since September 2025 and has used CVE-2024-3400 for initial access, with victims across manufacturing and critical infrastructure among other sectors. The report says Black Shrantac favors trusted tools and existing infrastructure over custom malware, which reduces visible indicators and complicates attribution.

The forward risk is persistence with little forensic residue. Once access is gained through exposed perimeter systems, defenders may be left with fewer artifacts to prove what was touched before data theft and extortion begin.

1 fonte · 15 apr

CVE-2024-3400

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 10 CRITICAL: a command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto… Impiego noto in campagne ransomware. EPSS 100% (100º percentile).

Data di correzione federale CISA 19 apr · data superata

Cronologia

Fonti

Part of the PlainSec briefing for 2026-04-26

Every edition of this story: Black Shrantac Turns Perimeter Flaws Into Quiet Extortion