Embargo

Embargo — Threat Actor Profile | ObscureIQ
ObscureIQ Threat Intelligence · Actor Profile

EmbargoConfidence: High

Ransomware (RaaS)

Motivation: Financial

1Attributed Breaches
HighAttribution Confidence
Ransomware (RaaS)Actor Type

Overview

A Rust-based operation active since around April 2024, to which TRM Labs tied roughly $34.2M in inflows, with US victims concentrated in healthcare, business services, and manufacturing. On-chain overlap with BlackCat/ALPHV suggests it may be a rebrand; its toolkit disables security solutions.

Tactics, Targeting & TTPs

Rust malware plus a toolkit that disables security solutions (ESET). On-chain overlap with BlackCat/ALPHV suggests Embargo may be a rebrand.

Source

Attribution draws on public threat-intelligence reporting · Established (multi-source). Primary source →

Were you exposed in one of these breaches?

Check your exposure privately, or request a tailored exposure audit.

Request Consultation