Embargo

MITRE ATT&CK: S1247 View on attack.mitre.org

Aliases: Embargo

First seen
2024-05-01 00:00:00
Malware type
ransomware, loader
Family
Malware family
Operating systems
esxi, linux, windows
Related IoCs
5 (5 malicious)
Last IoC activity
2026-07-30 22:56:51
Profile updated
2026-07-07 13:52:59

Targeted industries: financial-services healthcare-and-pharmaceutical government-and-public-sector technology-and-telecommunications

Context

Embargo is a ransomware variant written in Rust that has been active since at least May 2024. Embargo ransomware operations are associated with “double extortion” ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Embargo ransomware has been known to be delivered through a loader known as MDeployer which also leverages a malware component known as MS4Killer that facilitates termination of processes operating on the victim hosts. Embargo is also reportedly a Ransomware as a Service (RaaS).

Recent IoC activity

5 malicious indicators in Maltiverse are attributed to Embargo (S1247). The 5 most recently updated:

Detection coverage

  • 389 Sigma rules

Malware & tools used

  • Service Stop (attack-pattern)
  • Mutual Exclusion (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Financial Theft (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Safe Mode Boot (attack-pattern)
  • Native API (attack-pattern)
  • Process Discovery (attack-pattern)
  • Modify Registry (attack-pattern)
  • Inhibit System Recovery (attack-pattern)
  • Selective Exclusion (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Network Share Discovery (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • System Service Discovery (attack-pattern)
  • Scheduled Task (attack-pattern)
  • File Deletion (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Service Execution (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Windows Service (attack-pattern)

Used by threat actors

  • Storm-0501 (threat-actor)
  • Storm-0501 Hybrid Cloud Compromise (campaign)

Reports & references

  • ransomlook.io — Embargo (report)
  • sentinelone.com — Embargo Ransomware New Raas On The Scene (report)
  • zscaler.com — Technical Analysis Embargo Ransomware (report)
  • Trend Micro — Embargo Ransomware Raas Analysis (report)
  • MITRE ATT&CK — S1247 (report)
  • cyble.com — The Rust Revolution New Embargo Ransomware Steps In (report)
  • ESET — Embargo Ransomware Rocknrust (report)

External references