Embargo

S1247

Malware.View on attack.mitre.org

About this malware

Embargo is a ransomware variant written in Rust that has been active since at least May 2024. Embargo ransomware operations are associated with “double extortion” ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Embargo ransomware has been known to be delivered through a loader known as MDeployer which also leverages a malware component known as MS4Killer that facilitates termination of processes operating on the victim hosts. Embargo is also reportedly a Ransomware as a Service (RaaS).

Techniques used22

Procedure examples22

TechniqueProcedure example
T1007
System Service Discovery

Embargo has obtained active services running on the victim’s system through the functions `OpenSCManagerW()` and `EnumServicesStatusExW()`.

T1027.013
Encrypted/Encoded File

Embargo has encrypted both MDeployer and MS4 Killer payloads with RC4.

T1053.005
Scheduled Task

Embargo has obtained persistence of the loader MDeployer by creating a scheduled task named “Perf_sys.”

T1057
Process Discovery

Embargo has utilized MS4Killer to detect running processes on the victim device. Embargo has also captured a snapshot of active running processes using the Windows API `CreateToolHelp32Snapshot()`.

T1059.003
Windows Command Shell

Embargo has utilized a BAT script to disable security solutions.

T1068
Exploitation for Privilege Escalation

Embargo has leveraged MS4Killer to deliver a vulnerable driver to the victim device, sometimes referred to as Bring Your Own Vulnerable Driver (BYOVD). Embargo has utilized the vulnerable driver probmon.sys version 3.0.0.4 which had a revoked certificated from “ITM System Co.,LTD.”

T1070.004
File Deletion

Embargo has leveraged MDeployer to terminate the MS4Killer process, delete the decrypted payload files and a driver file dropped by MS4killer, and reboot the system.

T1083
File and Directory Discovery

Embargo has searched for folders, subfolders and other networked or mounted drives for follow on encryption actions. Embargo has also iterated device volumes using `FindFirstVolumeW()` and `FindNextVolumeW()` functions and then calls the `GetVolumePathNamesForVolumeNameW()` function to retrieve a list of drive letters and mounted folder paths for each specified volume.

T1106
Native API

Embargo has leveraged Windows Native API functions to execute its operations.

T1112
Modify Registry

Embargo has modified and deleted Registry keys to add services, and to disable Security Solutions such as Windows Defender.

T1135
Network Share Discovery

Embargo has searched for folders, subfolders and other networked or mounted drives for follow-on encryption actions.

T1140
Deobfuscate/Decode Files or Information

Embargo has utilized MDeployer to decrypt two payloads that contain MS4Killer toolkit b.cache and the Embargo ransomware executable a.cache with a hardcoded RC4 key `wlQYLoPCil3niI7x8CvR9EtNtL/aeaHrZ23LP3fAsJogVTIzdnZ5Pi09ZVeHFkiB`.

T1480.002
Mutual Exclusion

Embargo has utilized a hardcoded mutex name of “LoadUpOnGunsBringYourFriends” using the `CreateMutexW()` function. Embargo has also utilized a hardcoded mutex name of “IntoTheFloodAgainSameOldTrip."

T1486
Data Encrypted for Impact

Embargo has the ability to encrypt files with the ChaCha20 and Curve25519 cryptographic algorithms. Embargo also has the ability to encrypt system data and add a random six-letter extension consisting of hexadecimal characters such as ".b58eeb" or “.3d828a” to encrypted files.

T1489
Service Stop

Embargo has terminated active processes and services based on a hardcoded list using the `CloseServiceHandle()` function. Embargo has also leveraged MS4Killer to terminate processes contained in an embedded list of security software process names that were XOR-encrypted.

View all 22 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. Cyble Embargo Ransomware May 2024 Open source
    Cyble. (2024, May 24). The Rust Revolution: New Embargo Ransomware Steps In. Retrieved October 19, 2025.
  2. ESET Embargo Ransomware October 2024 Open source
    Jan Holman, Tomas Zvara. (2024, October 23). Embargo ransomware: Rock’n’Rust. Retrieved October 19, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.