BlackShrantac is a data-theft extortion group active since at least September 2025. The group is characterized by encryption-less ransomware-style operations in which it steals large volumes of victim data and demands payment to prevent public disclosure rather than deploying file-encrypting malware. It has been tracked under the names BlackShrantac and Black Shrantac. Victim reporting indicates broad, opportunistic targeting across multiple countries, including organizations in North America, Europe, Asia, the Middle East, and Africa. Reported victims span business environments such as transportation and fleet telematics, food and beverage, manufacturing, and cybersecurity-related firms, with additional evidence of attacks affecting South Korean and Japanese organizations. The group appears to favor organizations holding substantial data volumes rather than a single narrowly defined vertical. Observed tradecraft includes phishing with malicious attachments and supply-chain compromise for initial access. BlackShrantac has also been associated with use of command and scripting interpreters including PowerShell, Windows shell, and Bash during intrusion activity. Persistence has been linked to scheduled tasks and startup or autorun modifications. Operationally, the group’s hallmark behavior is large-scale exfiltration followed by extortion via a leak-site model, making anomalous outbound data transfer a notable behavioral indicator. BlackShrantac is best understood as an extortion-focused leak-site actor rather than a conventional encrypting ransomware operator.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group highlighted for a manufacturing-sector attack in Japan that resulted in a large data breach.
Data-theft extortion group that focuses on stealing large volumes of data and demanding payment to prevent public release rather than encrypting victim files.
BlackShrantac is a ransomware group targeting technology and telematics providers in Australia, exfiltrating company data for extortion.
BlackShrantac is mentioned as an active ransomware group in November 2025.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.