Embargo
MITRE ATT&CK: S1247 View on attack.mitre.org
Aliases: Embargo
- First seen
- 2024-05-01 00:00:00
- Malware type
- ransomware, loader
- Family
- Malware family
- Operating systems
- esxi, linux, windows
- Related IoCs
- 5 (5 malicious)
- Last IoC activity
- 2026-07-30 22:56:51
- Profile updated
- 2026-07-07 13:52:59
Targeted industries: financial-services healthcare-and-pharmaceutical government-and-public-sector technology-and-telecommunications
Context
Embargo is a ransomware variant written in Rust that has been active since at least May 2024. Embargo ransomware operations are associated with “double extortion” ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Embargo ransomware has been known to be delivered through a loader known as MDeployer which also leverages a malware component known as MS4Killer that facilitates termination of processes operating on the victim hosts. Embargo is also reportedly a Ransomware as a Service (RaaS).
Recent IoC activity
5 malicious indicators in Maltiverse are attributed to Embargo (S1247). The 5 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 0d2619844a3ab68ee18c3a4768b10e6b8aea31143023277883b7ff9f7a9e55ca | 2026-07-30 | 1 |
| file sample | 023d722cbbdd04e3db77de7e6e3cfeabcef21ba5b2f04c3f3a33691801dd45eb | 2026-07-30 | 2 |
| file sample | 2026-07-26_657d940f97fad1d58e335e5f810e0154_akira_elex_glassworm_poet-rat | 2026-07-26 | 1 |
| file sample | 5b2988629166055e31f783637d272bfa8f74b836621db30e16b7fb9440f979eb | 2026-07-22 | 2 |
| file sample | 01712a5e443efb4aa43ef3f8b38a4245cb0d0c1bf13b8d3ac4207247a44f7ab4 | 2026-07-22 | 1 |
Detection coverage
- 389 Sigma rules
Malware & tools used
- Service Stop (attack-pattern)
- Mutual Exclusion (attack-pattern)
- Exploitation for Privilege Escalation (attack-pattern)
- Financial Theft (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Safe Mode Boot (attack-pattern)
- Native API (attack-pattern)
- Process Discovery (attack-pattern)
- Modify Registry (attack-pattern)
- Inhibit System Recovery (attack-pattern)
- Selective Exclusion (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Network Share Discovery (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Windows Command Shell (attack-pattern)
- System Service Discovery (attack-pattern)
- Scheduled Task (attack-pattern)
- File Deletion (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Service Execution (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- Windows Service (attack-pattern)
Used by threat actors
- Storm-0501 (threat-actor)
- Storm-0501 Hybrid Cloud Compromise (campaign)
Reports & references
- ransomlook.io — Embargo (report)
- sentinelone.com — Embargo Ransomware New Raas On The Scene (report)
- zscaler.com — Technical Analysis Embargo Ransomware (report)
- Trend Micro — Embargo Ransomware Raas Analysis (report)
- MITRE ATT&CK — S1247 (report)
- cyble.com — The Rust Revolution New Embargo Ransomware Steps In (report)
- ESET — Embargo Ransomware Rocknrust (report)