ATT&CKReferencesESET Embargo Ransomware October 2024

ESET Embargo Ransomware October 2024

Jan Holman, Tomas Zvara. (2024, October 23). Embargo ransomware: Rock’n’Rust. Retrieved October 19, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareEmbargo

Embargo has encrypted both MDeployer and MS4 Killer payloads with RC4.

T1053.005
Scheduled Task
MalwareEmbargo

Embargo has obtained persistence of the loader MDeployer by creating a scheduled task named “Perf_sys.”

T1057
Process Discovery
MalwareEmbargo

Embargo has utilized MS4Killer to detect running processes on the victim device. Embargo has also captured a snapshot of active running processes using the Windows API `CreateToolHelp32Snapshot()`.

T1059.003
Windows Command Shell
MalwareEmbargo

Embargo has utilized a BAT script to disable security solutions.

T1068
Exploitation for Privilege Escalation
MalwareEmbargo

Embargo has leveraged MS4Killer to deliver a vulnerable driver to the victim device, sometimes referred to as Bring Your Own Vulnerable Driver (BYOVD). Embargo has utilized the vulnerable driver probmon.sys version 3.0.0.4 which had a revoked certificated from “ITM System Co.,LTD.”

T1070.004
File Deletion
MalwareEmbargo

Embargo has leveraged MDeployer to terminate the MS4Killer process, delete the decrypted payload files and a driver file dropped by MS4killer, and reboot the system.

T1112
Modify Registry
MalwareEmbargo

Embargo has modified and deleted Registry keys to add services, and to disable Security Solutions such as Windows Defender.

T1140
Deobfuscate/Decode Files or Information
MalwareEmbargo

Embargo has utilized MDeployer to decrypt two payloads that contain MS4Killer toolkit b.cache and the Embargo ransomware executable a.cache with a hardcoded RC4 key `wlQYLoPCil3niI7x8CvR9EtNtL/aeaHrZ23LP3fAsJogVTIzdnZ5Pi09ZVeHFkiB`.

T1480.002
Mutual Exclusion
MalwareEmbargo

Embargo has utilized a hardcoded mutex name of “LoadUpOnGunsBringYourFriends” using the `CreateMutexW()` function. Embargo has also utilized a hardcoded mutex name of “IntoTheFloodAgainSameOldTrip."

T1486
Data Encrypted for Impact
MalwareEmbargo

Embargo has the ability to encrypt files with the ChaCha20 and Curve25519 cryptographic algorithms. Embargo also has the ability to encrypt system data and add a random six-letter extension consisting of hexadecimal characters such as ".b58eeb" or “.3d828a” to encrypted files.

T1489
Service Stop
MalwareEmbargo

Embargo has terminated active processes and services based on a hardcoded list using the `CloseServiceHandle()` function. Embargo has also leveraged MS4Killer to terminate processes contained in an embedded list of security software process names that were XOR-encrypted.

T1543.003
Windows Service
MalwareEmbargo

Embargo has created persistence through the DLL variant of the MDeployer toolkit by creating a service called irnagentd that launches after the system is rebooted in Safe Mode.

T1547.001
Registry Run Keys / Startup Folder
MalwareEmbargo

Embargo has modified the Windows Registry to start a custom service named irnagentd in Safe Mode.

T1569.002
Service Execution
MalwareEmbargo

Embargo has created a service named irnagentd that executed the MDeployer loader after the system is rebooted in Safe Mode.

T1657
Financial Theft
MalwareEmbargo

Embargo has been leveraged in double-extortion ransomware, exfiltrating files then encrypting them, to prompt victims to pay a ransom.

T1688
Safe Mode Boot
MalwareEmbargo

Embargo has used a DLL variant of MDeployer to disable security solutions through Safe Mode.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.