Ransomware · 168 giorni fa

Black Shrantac Turns Perimeter Flaws Into Quiet Extortion

Black Shrantac is not trying to be noisy. It is using a perimeter flaw to get in, then leaning on legitimate admin tools so the intrusion looks like normal activity. That makes the usual malware-focused detection playbook miss the point: the danger is sparse telemetry and a faster path to double extortion.

Marlink says the group has been active since September 2025 and has used CVE-2024-3400 for initial access, with victims across manufacturing and critical infrastructure among other sectors. The report says Black Shrantac favors trusted tools and existing infrastructure over custom malware, which reduces visible indicators and complicates attribution.

The forward risk is persistence with little forensic residue. Once access is gained through exposed perimeter systems, defenders may be left with fewer artifacts to prove what was touched before data theft and extortion begin.

CVE-2024-3400

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 10 CRITICAL: a command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto… Impiego noto in campagne ransomware. EPSS 100% (100º percentile).

Data di correzione federale CISA 19 apr · data superata

Cronologia

Fonti

1 fonte che coprono questa storia

Entità

Part of the PlainSec briefing for 2026-05-04

Editions