Cyble. (2024, May 24). The Rust Revolution: New Embargo Ransomware Steps In. Retrieved October 19, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareEmbargo | Embargo has obtained active services running on the victim’s system through the functions `OpenSCManagerW()` and `EnumServicesStatusExW()`. |
| T1057 Process Discovery |
MalwareEmbargo | Embargo has utilized MS4Killer to detect running processes on the victim device. Embargo has also captured a snapshot of active running processes using the Windows API `CreateToolHelp32Snapshot()`. |
| T1083 File and Directory Discovery |
MalwareEmbargo | Embargo has searched for folders, subfolders and other networked or mounted drives for follow on encryption actions. Embargo has also iterated device volumes using `FindFirstVolumeW()` and `FindNextVolumeW()` functions and then calls the `GetVolumePathNamesForVolumeNameW()` function to retrieve a list of drive letters and mounted folder paths for each specified volume. |
| T1106 Native API |
MalwareEmbargo | Embargo has leveraged Windows Native API functions to execute its operations. |
| T1135 Network Share Discovery |
MalwareEmbargo | Embargo has searched for folders, subfolders and other networked or mounted drives for follow-on encryption actions. |
| T1480.002 Mutual Exclusion |
MalwareEmbargo | Embargo has utilized a hardcoded mutex name of “LoadUpOnGunsBringYourFriends” using the `CreateMutexW()` function. Embargo has also utilized a hardcoded mutex name of “IntoTheFloodAgainSameOldTrip." |
| T1486 Data Encrypted for Impact |
MalwareEmbargo | Embargo has the ability to encrypt files with the ChaCha20 and Curve25519 cryptographic algorithms. Embargo also has the ability to encrypt system data and add a random six-letter extension consisting of hexadecimal characters such as ".b58eeb" or “.3d828a” to encrypted files. |
| T1489 Service Stop |
MalwareEmbargo | Embargo has terminated active processes and services based on a hardcoded list using the `CloseServiceHandle()` function. Embargo has also leveraged MS4Killer to terminate processes contained in an embedded list of security software process names that were XOR-encrypted. |
| T1490 Inhibit System Recovery |
MalwareEmbargo | Embargo has cleared files from the recycle bin by invoking `SHEmptyRecycleBinW()` and disabled Windows recovery through `C:\Windows\System32\cmd.exe /q /c bcdedit /set {default} recoveryenabled no`. |
| T1657 Financial Theft |
MalwareEmbargo | Embargo has been leveraged in double-extortion ransomware, exfiltrating files then encrypting them, to prompt victims to pay a ransom. |
| T1679 Selective Exclusion |
MalwareEmbargo | Embargo has avoided encrypting specific files and directories by leveraging a regular expression within the ransomware binary. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.