Embargo — Malware Profile
Embargo is a ransomware variant written in Rust that has been active since at least May 2024. Embargo ransomware operations are associated with “double extortion” ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Embargo ransomware has been known to be delivered through a loader known as MDeployer which also leverages a malware component known as MS4Killer that facilitates termination of processes operating on the victim hosts. Embargo is also reportedly a Ransomware as a Service (RaaS).
MITRE ATT&CK techniques (22)
- T1007 System Service Discovery
- T1027.013 Encrypted/Encoded File
- T1053.005 Scheduled Task
- T1057 Process Discovery
- T1059.003 Windows Command Shell
- T1068 Exploitation for Privilege Escalation
- T1070.004 File Deletion
- T1083 File and Directory Discovery
- T1106 Native API
- T1112 Modify Registry
- T1135 Network Share Discovery
- T1140 Deobfuscate/Decode Files or Information
- T1480.002 Mutual Exclusion
- T1486 Data Encrypted for Impact
- T1489 Service Stop
- T1490 Inhibit System Recovery
- T1543.003 Windows Service
- T1547.001 Registry Run Keys / Startup Folder
- T1569.002 Service Execution
- T1657 Financial Theft
- T1679 Selective Exclusion
- T1688 Safe Mode Boot