Netskope Threat Labs

Embargo

ATP Sandbox Adv. HeuristicsAV

Embargo is a Rust based ransomware variant active since at least May 2024 that runs double extortion operations, exfiltrating data before encryption and threatening publication if victims do not pay. Its deliveries used the MDeployer loader together with the MS4Killer component, which terminates processes on victim hosts to clear the way for encryption.

First seen
May 2024
Last seen
October 2026

22 techniques across 7 tactics.

TA0002 Execution

TA0003 Persistence

  • T1543Create or Modify System Process
  • T1547Boot or Logon Autostart Execution

TA0004 Privilege Escalation

  • T1068Exploitation for Privilege Escalation

TA0005 Stealth

TA0007 Discovery

  • T1007System Service Discovery
  • T1057Process Discovery
  • T1083File and Directory Discovery
  • T1135Network Share Discovery

TA0040 Impact

TA0112 Defense Impairment

Alert Name
Gen:Variant.Ransom.Embargo.1
Gen:Variant.Ransom.Embargo.2
Trojan.Ransom.Embargo.2
Win32.Ransomware.Embargo
Win64.Trojan.Embargo