Jan Holman, Tomas Zvara. (2024, October 23). Embargo ransomware: Rock’n’Rust. Retrieved October 19, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareEmbargo | Embargo has encrypted both MDeployer and MS4 Killer payloads with RC4. |
| T1053.005 Scheduled Task |
MalwareEmbargo | Embargo has obtained persistence of the loader MDeployer by creating a scheduled task named “Perf_sys.” |
| T1057 Process Discovery |
MalwareEmbargo | Embargo has utilized MS4Killer to detect running processes on the victim device. Embargo has also captured a snapshot of active running processes using the Windows API `CreateToolHelp32Snapshot()`. |
| T1059.003 Windows Command Shell |
MalwareEmbargo | Embargo has utilized a BAT script to disable security solutions. |
| T1068 Exploitation for Privilege Escalation |
MalwareEmbargo | Embargo has leveraged MS4Killer to deliver a vulnerable driver to the victim device, sometimes referred to as Bring Your Own Vulnerable Driver (BYOVD). Embargo has utilized the vulnerable driver probmon.sys version 3.0.0.4 which had a revoked certificated from “ITM System Co.,LTD.” |
| T1070.004 File Deletion |
MalwareEmbargo | Embargo has leveraged MDeployer to terminate the MS4Killer process, delete the decrypted payload files and a driver file dropped by MS4killer, and reboot the system. |
| T1112 Modify Registry |
MalwareEmbargo | Embargo has modified and deleted Registry keys to add services, and to disable Security Solutions such as Windows Defender. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareEmbargo | Embargo has utilized MDeployer to decrypt two payloads that contain MS4Killer toolkit b.cache and the Embargo ransomware executable a.cache with a hardcoded RC4 key `wlQYLoPCil3niI7x8CvR9EtNtL/aeaHrZ23LP3fAsJogVTIzdnZ5Pi09ZVeHFkiB`. |
| T1480.002 Mutual Exclusion |
MalwareEmbargo | Embargo has utilized a hardcoded mutex name of “LoadUpOnGunsBringYourFriends” using the `CreateMutexW()` function. Embargo has also utilized a hardcoded mutex name of “IntoTheFloodAgainSameOldTrip." |
| T1486 Data Encrypted for Impact |
MalwareEmbargo | Embargo has the ability to encrypt files with the ChaCha20 and Curve25519 cryptographic algorithms. Embargo also has the ability to encrypt system data and add a random six-letter extension consisting of hexadecimal characters such as ".b58eeb" or “.3d828a” to encrypted files. |
| T1489 Service Stop |
MalwareEmbargo | Embargo has terminated active processes and services based on a hardcoded list using the `CloseServiceHandle()` function. Embargo has also leveraged MS4Killer to terminate processes contained in an embedded list of security software process names that were XOR-encrypted. |
| T1543.003 Windows Service |
MalwareEmbargo | Embargo has created persistence through the DLL variant of the MDeployer toolkit by creating a service called irnagentd that launches after the system is rebooted in Safe Mode. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareEmbargo | Embargo has modified the Windows Registry to start a custom service named irnagentd in Safe Mode. |
| T1569.002 Service Execution |
MalwareEmbargo | Embargo has created a service named irnagentd that executed the MDeployer loader after the system is rebooted in Safe Mode. |
| T1657 Financial Theft |
MalwareEmbargo | Embargo has been leveraged in double-extortion ransomware, exfiltrating files then encrypting them, to prompt victims to pay a ransom. |
| T1688 Safe Mode Boot |
MalwareEmbargo | Embargo has used a DLL variant of MDeployer to disable security solutions through Safe Mode. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.