Black Shrantac Turns Perimeter Flaws Into Quiet Extortion

Black Shrantac is not trying to be noisy. It is using a perimeter flaw to get in, then leaning on legitimate admin tools so the intrusion looks like normal activity. That makes the usual malware-focused detection playbook miss the point: the danger is sparse telemetry and a faster path to double extortion. Marlink says the group has been active since September 2025 and has used CVE-2024-3400 for initial access, with victims across manufacturing and critical infrastructure among other sectors. The report says Black Shrantac favors trusted tools and existing infrastructure over custom malware, which reduces visible indicators and complicates attribution. The forward risk is persistence with little forensic residue. Once access is gained through exposed perimeter systems, defenders may be left with fewer artifacts to prove what was touched before data theft and extortion begin.

Part of the PlainSec briefing for 2026-05-04

Sources