BlackShrantac

Threat Actor

BlackShrantac ransomware group is a new and sparsely documented threat actor, believed to have emerged in 2025. Indicators suggest it is part of the ongoing wave of short-lived or rebranded ransomware operations that often appear as law-enforcement pressure disrupts established groups.
BlackShrantac follows the now-standard double extortion model, encrypting victim systems while threatening to leak stolen data if the victim does not meet ransom demands. To that end, targets appear to be small to mid-sized organizations. Attacks focus on maximizing operational disruption rather than long-term persistence.

Incidents Associated with this Threat

Malware Used by this Threat Actor

No malware identified for this threat actor.