Description
Embargo is a Rust based ransomware variant active since at least May 2024 that runs double extortion operations, exfiltrating data before encryption and threatening publication if victims do not pay. Its deliveries used the MDeployer loader together with the MS4Killer component, which terminates processes on victim hosts to clear the way for encryption.
Stats
- First seen
- May 2024
- Last seen
- October 2026
MITRE ATT&CK techniques
22 techniques across 7 tactics.
TA0002 Execution
TA0003 Persistence
TA0004 Privilege Escalation
- T1068Exploitation for Privilege Escalation
TA0005 Stealth
TA0007 Discovery
TA0040 Impact
Associated groups
Alert name variants
| Alert Name |
|---|
| Gen:Variant.Ransom.Embargo.1 |
| Gen:Variant.Ransom.Embargo.2 |
| Trojan.Ransom.Embargo.2 |
| Win32.Ransomware.Embargo |
| Win64.Trojan.Embargo |