Embargo

Active
Embargo is a Rust-based ransomware-as-a-service group that emerged in April 2024, primarily targeting US healthcare, manufacturing, and business services organizations using double extortion, assessed as a potential successor to BlackCat/ALPHV with over $34 million in ransom proceeds.
41 Victims
Apr 17, 2024 First Discovered
Sep 9, 2026 Last Discovered
7 Days Inactive
0% Infostealer
1/1 Sites Online
Known Locations (1)
EMBARGO
embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion
Tools Used
DefenseEvasion
s4killer (Minifilter Driver)
LOLBAS
BCDEdit, ServiceControl (sc.exe)
Intelligence
Victims (41)

Detailed victim list temporarily unavailable

This group has 41 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.