LIVE
LATEST THREAT: Arcus Media: The RaaS Operation Targeting Healthcare and Critical Infrastructure THREAT ALERT ACTIVE
Intelligence DB / Group Profile Embargo

Embargo Ransomware: Rust-Based RaaS Targeting Enterprise and Healthcare

Embargo emerged in mid-2024 deploying a custom Rust-based ransomware and locker toolset against enterprise targets in North America and Europe. With double extortion infrastructure, a dedicated leak site, and affiliate recruitment, Embargo operates a mature RaaS model despite its relative youth. This profile covers their TTPs, victim profile, and defensive considerations.

By Ransomware Tracker ·
EmbargoransomwareRustRaaSMDeployerMS4KillerEDR-killerhealthcareenterprisedouble-extortionESXisafe-modeALPHV2026
Threat Level
8/10
Sectors Targeted
healthcare
technology
manufacturing
financial-services
legal
Ransomware Family
Embargo

Embargo appeared in mid-2024 operating a double extortion model with a distinct technical characteristic: their toolset is written in Rust, including both the primary ransomware encryptor and a companion EDR-killing utility. In the ransomware ecosystem, Rust has become a flag for groups with engineering capability — ALPHV/BlackCat demonstrated the language’s cross-platform advantages and evasion characteristics, and several successor groups have adopted it.

Embargo is not confirmed to be an ALPHV successor, but the timing of their emergence (shortly after ALPHV’s law enforcement disruption and subsequent exit scam in March 2024) and some operational similarities have prompted speculation about personnel overlap or toolset inheritance.

Technical profile

MDeployer is the Embargo group’s primary deployment tool — a Rust-written loader that manages staging, execution, and the orchestration of the encryption campaign across a compromised environment. MDeployer handles the pre-encryption preparation phase: clearing shadow copies, disabling backup agents, stopping database services, and ensuring the encryption run executes with maximum coverage.

MS4Killer is the companion EDR-disabling utility, also Rust-written. Its primary function is terminating or disabling security product processes before encryption begins. It uses a bring-your-own-vulnerable-driver (BYOVD) technique — deploying a signed but vulnerable kernel driver to gain the kernel access needed to terminate protected security processes. The specific driver used by Embargo has varied across campaigns, suggesting the group actively rotates BYOVD components as drivers are added to blocklists.

ESXi targeting: Like most mature ransomware groups, Embargo includes a Linux/ESXi encryptor variant. Attacks against VMware ESXi hypervisors maximise the impact per compromised host — a single ESXi box may run dozens of virtual machines, all of which encrypt in parallel once the hypervisor-level encryptor executes. Embargo’s ESXi component operates in safe mode to reduce the EDR coverage gap at the hypervisor layer.

Safe mode reboot: Some Embargo campaigns use the Windows safe mode restart technique to execute encryption. By rebooting into safe mode and configuring the encryptor to run as the safe mode startup executable, the group can execute encryption with most security products offline. This is a technique associated with REvil and Black Basta and indicates operational knowledge of EDR avoidance tradecraft.

Initial access

Embargo does not appear to operate its own initial access infrastructure. Available incident data points to initial access broker (IAB) purchases and direct exploitation of externally exposed services — primarily RDP, VPN appliances with unpatched vulnerabilities, and in some cases phishing with commodity RAT delivery.

VPN appliances have been a consistent initial access vector across the ransomware ecosystem throughout 2024-2026. The Cisco ASA, Fortinet FortiGate, and Ivanti Connect Secure exploitation waves produced significant volumes of compromised VPN credentials and foothold access that IABs monetised through RaaS affiliate networks. Embargo’s activity is consistent with purchasing access from the established IAB market rather than developing bespoke exploitation capability.

Victim profile

Embargo’s known victim list skews toward North American healthcare, legal services, and mid-market technology companies, with a secondary presence in European manufacturing. Healthcare sector targeting is not unusual in the ransomware ecosystem — the sector’s pressure to restore operations quickly creates negotiating leverage for attackers — but it is notable given the increasingly aggressive law enforcement and regulatory response to healthcare ransomware in the US and EU.

Reported ransom demands from Embargo incidents range from approximately $800,000 to $8 million, consistent with targeting organisations large enough to have cyber insurance coverage but below the thresholds that attract the most intense law enforcement attention. This suggests deliberate targeting decisions or affiliate selection criteria calibrated for sustainable operations.

Data leak infrastructure

Embargo operates a dedicated data leak site on Tor, consistent with the standard double extortion model. Victims who do not pay within the negotiation window have data published to the site in stages — partial publication initially, then full publication — as a negotiating pressure mechanism. The site has been operational continuously since Embargo’s emergence and has published data from incidents across multiple sectors.

The leak site includes a negotiation interface for victims, which indicates a reasonable operational structure for handling the affiliate-side customer service function that RaaS models require.

Relationship to the affiliate ecosystem

Embargo actively recruits affiliates through the established Russian-language cybercriminal forums. Affiliate recruitment messaging emphasises the Rust toolset’s evasion characteristics, the EDR-killing capability, and competitive revenue share. The group appears to vet affiliates — the victim profile shows consistency in targeting approach that suggests either centralised targeting or effective affiliate selection criteria.

Whether Embargo represents a continuation of ALPHV/BlackCat personnel, tooling, or relationships remains unconfirmed. The technical sophistication of the Rust toolset, the operational structure, and the timing are suggestive but not conclusive. Multiple ransomware groups have independently developed Rust-based tools in the post-ALPHV period.

Detection and defence considerations

The MS4Killer BYOVD component is detectable via kernel driver load events when the vulnerable driver is dropped and loaded. Windows event logs record driver loads (Event ID 6 in Sysmon), and checking loaded drivers against known-vulnerable driver lists (as maintained by LOLDrivers.io and Elastic) provides pre-encryption detection opportunity.

Safe mode reboot for encryption evasion is detectable via unexpected reboot events followed by RunOnce/startup registry key modifications. Monitoring for HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal registry modifications is a useful hunting query.

Embargo’s ESXi targeting follows the pattern of enumerating virtual machines with esxcli vm process list before shutdown and encryption. Monitoring for unexpected VM management operations from non-standard accounts or at unusual times is the detection opportunity at the hypervisor layer.

For prevention, the primary controls are VPN appliance patching (Embargo’s primary initial access vector), RDP exposure reduction, and EDR coverage of the domains where MDeployer and MS4Killer execute. Both tools execute in user or service account contexts before acquiring elevated privileges — preventing that escalation is the chokepoint.

Current status

As of mid-2026, Embargo continues to operate. No law enforcement action has been publicly attributed to the group, and no decryptor has been released or made available through official channels. Victims who have not paid and have not restored from backup should not expect a free decryptor — the group shows no sign of operational disruption that would prompt key releases.

// Related Intelligence
Group Profile

Arcus Media: The RaaS Operation Targeting Healthcare and Critical Infrastructure

Group Profile

Spirals Ransomware: New Group Completes Full Attack Chain in Under 24 Hours

Group Profile

RansomExx: Long-Running Enterprise Ransomware Group Targeting Critical Infrastructure and Government