embargo
Ransomware group profile
Description
Embargo is a cybercriminal group that specializes in sophisticated ransomware attacks, employing double extortion tactics to pressure victims into paying ransoms. Active since at least 2019, they utilize custom malware and exploit zero-day vulnerabilities to penetrate targeted networks, with a particular focus on the healthcare and financial sectors.
Key insights
- •Known for double extortion tactics, where both encryption and data exfiltration pressure victims for ransom.
- •Targets include healthcare institutions, demanding ransoms as high as $10 million.
- •Exploits zero-day vulnerabilities and utilizes custom Rust-based malware to facilitate attacks.
- •Observes supply chain attack methodologies, compromising third-party services to reach clients.
- •Employs living-off-the-land techniques to evade detection, relying less on traditional malware.
Threat Level & Status Breakdown
For embargo · Based on incidents in selected period
Recent activity
Monthly attack count for embargo in the selected period
Intelligence
IOCs, YARA/Sigma rules, and related families for embargo
- eb878e71f8fbc7051eb2df9918bc3bf3
- 16a183486e98defb6aa7f643cc23df85fc408f99f3d71f31d3f6835ca2767d4c
- 341e4ee0d46bf6ac9a637610ea255bf1db9283802f25cb33ae1b2ae2d1cae57a
- a295ad637bcccfb3457af9e9af98d313c0a10ba0816698380b3c0eebb0643157
- 633bf13e4a3de387ffc86d161780d25947fe1359cc070cc06adf41c9a3d455b2
- 721383e30aafc3a53d3243a2feaf8f368aeb2138a8c394d0ea680d20966933fb
- 793c1c18f16a2190489e73e7d31f7db3
- f0ac3999d4020cd051052a0627a2056d
- b94ed039e0217addeb9cc24f8834c277f485d4b97cd36b3344a7cc4b420c2de3
- a049a13c6a3f9b9f58fd9cafe7699a50b8493864fae3ad381b3592e94b557b81
- 0128530b3fdd30021b98d2287d1cca26dc85204f8b0ca2f9b7e335376305526a
- 26e46e6799f16896ecbb17810aaff10ab17b7f675779ba1bb3b505659d476a2a
- 486357f444b5d9758d38c783d93b2083f596bef7da393079be75349779d17b90
- 468121e7d6952799f92940677268937c4c5f92ed
- 83d83f9e1223fdf580ae12ca106da1ea5e9ef136b4d029a85841abe5ca832497
- 0ebf9cc718a63ed6b532bcad67df6c268cd3f1c7117db26475f47af91c96fcc6
- 45c9bee7879ffae84388adfcab2f54b7791677539e0bb6e7cc9397c64568d5e3
- 3b5940eeb4d04fffddb81d737353f4b68e6d13607492c9f57f28f29a20e7f025
- 1ee3d12a7a4379870d8623b02c94170fe18c824762be6fb218bf2838135ccf7c
- 2779d6d1fa3998a50d8aa5d90532720c9d892eef7ca629a12793c42d29e15bac
- 484db9aa01ce99d8af7deda10ae4d765337f3b6df54ae187006d9511d8962265
- c0d06817b7a6e78aba0240a3d910b6494f712351e988d79826428395bbf5d247
- 520e5744c542c8458b9d1e68ca70a66ce81d9403ec4f4add2facdc3d7b2fd312
- 1bd286269dd07d78ade37084ce3a3fb814f06928
- 09e2829dc2ca4c53e61a09517e9e8b2b6f38a4981fef9b466a102344b43284f5
- 9b04a93e05ccff94667f04bffa7af600
- 231174bc50e726b736813d0e859523b1df8f01eca4704e9ef3161fb69d45e78a
- 8747a1c5a51d441f6445f507c3ed1708
- 9475a44efd6eba13a7b4a59d7fb4ae49255cd11456a2f769aa401ead875da998
- 2d65decce305e34dbd2a73b445cbbdb6addfc7ebb9cd119cf55e9f699d3695b7
- b7703a59c39a0d2f7ef6422945aaeaaf061431af0533557246397551b8eed505
- b71e52d80f59380556ce2aa5838189eceaadde8cc69da2691fddbfa1f9b7e1e6
- 9afa6d6dee7fb34db9a464993cf75c540652c262815044d840c18265761022ca
- 041890221e3cd31f6ed46cf9a9e5e04a7ea615c18290f6d48c7bd7ac0010e66c
- 51e278ff7922a43e24f9d828e4cd1aff07b0e154aa3ef74c1a17cfe8ba881dca
- dae21a14a359fb60167e8fb9e89a7cb3
- ce2fa3ccfacb02f65a828689ac0818c17c850aea1c934a5940e44444c79bf6d2
- 925b0338e74deaa1bcc233cb9e39633631789dca8321e33ccd72c87bfe2df935
- cd9ce6294991221e64a47a0b23b16ad1d6032dc7
- 2ca03597074ab1763f5e4e2e3fd25c3e6f3546731033ec0fa1cc4a11c16df57d
- 5a2c4e7f9c6625bad78ead4d22a6703a5917b6e32ce8ebf42284f96960e41ab4
- 1119992d5f93402beafb5fdbe43343bef30835d1e293bc8903f0787ee97e7c3d
- 9c7064b20fdef73984bd41870fd0edc70be8c2e43e37ad12e0d2109e65ae3b93
- 2d399bdcf749887217fee11a17d0b7cc
- 75bebbfd9e6aa31a103d548beb8951671e31968957599470401592ce5bea3634
- ae25c309efb5223b739c6bf617bcb49d3fe14c0821774fd2605b861955417396
- 8f20cc1d473b4ec55ecf7db773a4d073436106f17240b2c033effcaec598ad54
- 38327b44a268df179463f6a2fb14ab8c975a2df4
- f383dc5a491774587b9005c2b576cd97ee700d224ce55388d9754de42f3f9ea3
- bc958ab1a25e3095a097ddc5effc5d9d2b29ebfa4652f682171d28e84eb22995
- 0021e2be82a3fd4d0bff80d682066be265b6601a03ade6acbcc3c8ae1462b0db
- 028fc133175401f9c53946a2a5553b9fd0aeb7f4a58edcd6bb3eaa1996241c21
- 3d85e1639871ea477b6cc02970b8a0bd81a1d273838fbf900e7f3815b4052c96
- b72e7efb81e183d4116b58d441835a526dd2fc776645301e25158dfc5edfa014
- 046d9a410f5a7b16d7763339f2ba37e243419e58dcc732ba59b2f6296969f7fe
- fbfb915fc28366e382fe404cb472c10f26bb6bef0069d5b7edf69dd6281f38d7
- d03450544c747e83a033001f1d77ba792819f3ff9632905de0e5e223c190d67f
- ebffc9ced2dba66db9aae02c7ccd2759a36c5167df5cd4adb151b20e7eab173c
- d0f36bbc0c335770c3956058f7cff85480275594d65813bfa845c2bcde9b8b5b
- 54de95cc33834a2f877ba4842860af27
- 9544461a4c432684919701fd2484d34140cc31197fe9f5d2e49d39f2e56d37fd
- d329608064b13006e73309a6f6a819b6bc1392b80ad01946d04719da0b680955
- 645321d18a4787fbba8ffbc76ce61708041f125ef44b93537d5454c7d888e333
- 48da4805d163be6f30504a3ca78c8cfe353f036d3c717288ede7fb56df880159
- 67f357190b0a2e4df8b141637286e9f84dedeed26e6ba3e63cb3511b3d1ef9c2
- 397d1611cad8d6a13dcaafbbf6f74750ce7fe09a7e139d4d1b98d39fc2d445cb
- 7afe037e153d2a4568c076ba19f3715f4377fb38
- fa1aedc98f9a97247b7314b9bd7947fc5656d4c4
- 9e82ee5bde6b5d29281a3c280e6d1f2e
- 70cd5b1b001e7ccd85a3860e33cf70f68e4ecd50fdae33625e1737d67f6788c7
- 1868680dc786e87f68ee8354bb955a10e793584d0fd45207a5df47efb95d4db8
- 38a6b81cf54615852f36f5c8c34246c771dd4d8c2ba73f9f82e52361217fbc2a
- 9fede41802d946d68e30268a0d26a9eec6720f7401ea2b49082caebbfc65a35b
- 726e9dabafd319e22f040618fe9c9d011c3a09300938c5a1b8f316178620b70a
- d26614d0ac188f6502b7ecbfd11cf61a57628fddf71761c7ac7b641fddf7324d
- aeea6ec390853cce357232b68badd4adc5020fb560c248d5131643f684078248
- 1f368e247c37f8116c7913fb2c1c5f2e730299b3e3f39ee31d3cf64d8f47af7f
- 88abb68205b90d669a3764f06df971ce
- 5e3389a003aeb01780d553e0ab9f6a92f31dbf8ea9ad7e5a6d9278aedc6c5679
- 6979662446e21b55f649802534e7c15671c345830187a668d30a1d57c84019ab
- f99cdc7004005384d938d5416d94b8fcf337a5f2e590374ec16e5f77fbc8fa87
- 8031d3c5e6174ad8273faec192550f4f4a15816abf2c9f871b28f834b2753629
- a34053e0fd4fbbd142be60650cd7fa6a2986370f6413c4506dc7f9d5a056cd13
- 46fa4395a75290c709a493d4fce0bcf1197990f9740ad410cd0f80eacc2ef8f4
- b41b4d8521acc98cce07499dfc42385609241535b8784a768b736a5692a528ce
- a27ecfd1339f88f14c7ba505d1afa109e42d9270
- 4170da59bbd82f48eec4b882dd1e76c09d8e93e98480991352325ff9555825ce
- 1997d4c440d6b31e0cdd732d61f8c08b528e1d99b73be8a31c87b4332c8e6944
- ce22389a9f83b2be18ac11ecaac4d7f960abeab935944a46191d3e083f890842
- 31586848486ada1ccda0f7ea7ad95bff30b14518
- 6f54458b2e720a39cecbe5529ffe6d1d63218ecb5e7e893950a7d73967dd9ea9
- 4375f225aa24c2f4b8247f0daa50d3f22f09e80c082646882862007c67b09b64
- b16e217cdca19e00c1b68bdfb28ead53b20adeabd6edcd91542f9fbf48942877
- 0e3b8c5499f97af5de9b0cd4334cd8af0037085066acb053a4099fdf5288da6f
- e9c098870de84c5dd24ed4c22aa6e962
- df5ab9015833023a03f92a797e20196672c1d6525501a9f9a94a45b0904c7403
- 88fcfa78fc577bc261d72ac4b97effc55a0f81a0614d151c3f5cd962cd256a50
- 6ee94f6bdc4c4ed0fff621fec36c70ff093659ed
- f393c6402720273e00ece17ce1d67da0005020a112ea153be66c760bfe63f2e1
- 609ecc42114da039b0e64d8262740fd15f8e1f4860e6f269417c1e76b3c3b45b
- 6d377b23a089faa32934cbadd259a3c688004b0f
- f0015127fccbd072b382e92f33eaccf5037cafc6caa156167939004e5d5ce6ba
- 34404aef381c34086eb383f6c0def96771d8f1c5304c23ab9a99cda1a5c0a699
- 642b6a654092913a18bcc0a35407e6be4da71759ca133b553922bee670a2a32d
- b5aadbe3a79598dad4bfa6cd0bfd4916cd2cee63f7171a957bbb6c38b6f3b39f
- 22df46558edc06915f107e34f46c732b8dfeef2447807c7b258e5c0d12ac0160
- d9598cb857f48251aeec28d2f21adc002e4e58b3b6e405055878a0cfffafe38a
- 18a58ad14de16004d8488d77843d58225b425b9eed04fdbded65baa314a519cb
- 1bbbe4d800795f46fe400e1eff1cfd501f6353d717c940d8607d2090c2bce959
- 737d7a04e836e65133dab211cb41b073df3ca9e5422b8c8c10f6941a78eb1b4a
- 5c3f310216fa98e9201a01351d7164cafbfaf0192c4730ced1c4c3727f9bb02b
- a4d8f3ea69a94ea2dc63229eab4e9f68c17ad8a7e55b84bb289529acd6fee26c
- 47ec51b5f0ede1e70bd66f3f0152f9eb536d534565dbb7fcc3a05f542dbe4428
- 0523473a874691b2bbab7af7442de648
- 04116cca703ba468fcc56a42f1a7839826b0a2b5f362c9536992676d8eeec012
- 25e6a4ecf9642da2cb4c38e069c008dc8afdfb75f14d5fabca11d5b1f513578e
- 3e0f1b77bc926de21299b466dd67828cb24fc829ec2b38386f1280b07a2e1b95
- a244fde869a19cd9810260b250888229855420021a24e28f9b56f2659c08bc32
- 6289c65031454dbd206002af6e6ea43d95c9df467ff771eaf3b3b7480d7a1368
- 1e3c8880ad389eca72d1893563d70e669c3986dfe58f95d3b1f836f711c875d4
- bc65ed919988c8e4b8f5a1cd371745456601700a
- 623060cb082d244a2aee4a5680e8d1a1317202902a92aba816e302ffb9031dc6
- 5d6b9e80e12bfc595d4d26f6afb099b3cb471dd4
- d93f1230b2747e9bddbf4dfb007fd5108a0a4b784a4625a21b7afa6910ce883a
- 19aa99fe75f60f40e778366af1ef97b0
- 1d5af46bfec89fb37e004366a29a9041d9d6de96bc47bbb5ba9c9801f814c165
- 94c710b0ebe05aaf9e16f7a9377b55845aed56e578c6bad1e78b51c618c2ac15
- 1ed91cd00bebe45855d67ad9f530659d21650490cc7dcacef50c059a5470c9f7
- b3a1b0eabf370923ecda326c1f83f6d625c13ec7e958e16cf3a0ce0e4a3fed5f
- 6bc8e3505d9f51368ddf323acb6abc49
- 2f51f84ebd6c133370a5f2333eb82c85203b67b5
- dc1b1211a834189edc00ef10721d82438e443a6f
- b5ffd42b0c940f35e7aebc31eba70396d251eec207aa4ecd4a04988bc92c40e9
- e673386c6a1018590cbfda5238dd0b67a0f3f9e7e504e3fa3f0f8f67f6668aca
- adbcf63ff24c43e024273906c534281499d3a5524d81d70376ff8cda3a34c347
- faf815adedc9cc5d30695ac2c1beb03f5afa36a5564f7492b3d08d889bb8578e
- 6f19b8d15a60bd36a690df073785c143b037b337f2bee6ddce8df2bdbc25b266
- ec004f7e33d9ccfd0f35cea467574803a45c2005c21b69dfeddf98ad58d48a47
- e84270afa3030b48dc9e0c53a35c65aa
- 048ef8710021d69d55bc8e707dc390aed1490a886dc65000617ebbd69a9611bb
- ec9f4e87cf83438d329d92c236546305a3d8ffc0487e6ff740d1b00f8c125aa4
- 4c534fded266c8d88cd4ee8e04289ab998234d47617d8183b8fbe8f7bb4dd522
- 7106ad3e462493cf2ad66ed1738c770076612f8aba02b149944c585bd1728c67
- e99ca2da0149fcecece59ac5f502ad98a8bdb11d0fabbae50c51d6d7ec0542f3
- d13b08df74ca18a2dc1a841fe38f120357bf3619d22a2a6cd8e456cc23395a33
- 7027525a12e7a4cb9b5c468a72525ef5abc2be66a6e1eadd5ca5af00fc2aaefb
- 0287ba4cfc55cf8a705f752bcdc303f5113b0f1a51cf88c04b6cd501b2298132
- e04ba391e58dc4ba7abde511b22eeb163538a67e7759e33f2bef5934504fdb2c
TTPs & Attack Vectors
Tools, initial access, and MITRE ATT&CK techniques for embargo
T1486
T1486
T1490
T1490
T1071.001
T1071.001
T1562
T1562
T1021
T1021
T1105
T1105
T1059
T1059
T1021.001
T1021.001
T1041
T1041
T1080
T1080
T1547
T1547
Victims(12)
| Company | Domain | Country | Industry | Status | Discovered | |
|---|---|---|---|---|---|---|
| cipsoft.com | — | NL Netherlands | Healthcare | Claimed | about 1 month ago | |
| https://www.lagoonpark.com/ | — | US United States | Hospitality | Claimed | 2 months ago | |
| ludlums.com | ludlums.com | US United States | Manufacturing | Claimed | 2 months ago | |
| westport.com | westport.com | US United States | Technology | Claimed | 3 months ago | |
| seclore.com | seclore.com | IN India | Technology | Claimed | 3 months ago | |
| ubm.hu | ubm.hu | HU Hungary | Technology | Claimed | 3 months ago | |
| nch.com | nch.com | US United States | Technology | Claimed | 3 months ago | |
| lso.com | lso.com | LS Lesotho | Transportation | Claimed | 6 months ago | |
| ACTi.com | acti.com | TW Taiwan | Technology | Claimed | 7 months ago | |
| usadebusk.com | usadebusk.com | US United States | Professional Services | Claimed | 9 months ago | |
| Heart of America Medical Centr (HAMC) | — | US United States | Healthcare | Claimed | about 1 month ago | |
| rotaryeng.com.sg | rotaryeng.com.sg | SG Singapore | Manufacturing | Claimed | 12 months ago |
Affected countries(22)
Countries where this group has been reported to target or leak victims.