Embargo
Embargo (canonical naming) is a Rust-based Ransomware-as-a-Service (RaaS) operation emerging around April 2024 with significant operational + technical + on-chain similarities to BlackCat (ALPHV) which conducted apparent March 2024 exit scam following Change Healthcare $22 million ransom payment per IBM X-Force November 2025 context analysis ("In March 2024, BlackCat successfully compromised Change Healthcare and received a ransom payment of USD 22 million in Bitcoin. But here's where things get weird: Immediately after taking payment, BlackCat closed its doors, citing 'the feds' as the reason for the shutdown"); suspected BlackCat/ALPHV successor attribution via TRM Labs canonical August 2025 Unmasking Embargo Ransomware Deep Dive analysis ("TRM assesses that Embargo may be a rebrand or successor to BlackCat, also known as ALPHV, based on both on-chain and off-chain similarities. Technical overlaps include the use of the Rust programming language, a similarly designed data leak site, and on-chain overlaps via shared wallet infrastructure") + The Record / Recorded Future News + Cyble researchers leak site + UI + Rust variant similarities documentation + SC Media October 2024 Summerville SC coverage + GridInSoft canonical ALPHV Reborn analysis with honest attribution caveat that BlackCat-successor assessment is moderate-confidence per TRM Labs and group has not publicly claimed or denied lineage.
standalone cluster paralleling hunters_international + cactus + trigona in v0.1.160 2022-2025 post-takedown + emerging RaaS cell; operational target profile United States primary geographic per TRM Labs + signature U.S. healthcare- focused victim targeting (American Associated Pharmacies + Memorial Hospital and Manor in Georgia + Weiser Memorial Hospital in Idaho with ransom demands reaching $1.3 million) + business services + manufacturing secondary sectors + signature U.S. municipal government attack (Town of Summerville South Carolina with 1.71 TB stolen from police department October 2024)
operational attack architecture: (1) cluster-defining April 2024 emergence post-BlackCat March 2024 exit scam timing establishing successor-operation timing pattern.
(2) cluster-defining Rust programming language matching BlackCat tradecraft with Rust adopted for detection evasion + parallelism + cross-platform compatibility consistent with BlackCat-pioneered Rust ransomware tradecraft.
(3) cluster-defining similar leak site design + user interface to BlackCat per Cyble researchers indicating shared- design-team or shared-codebase signature.
(4) cluster-defining on-chain wallet infrastructure overlap with BlackCat funds per TRM Labs Graph Visualizer evidence ("TRM's Graph Visualizer showing a small Embargo wallet cluster with incoming BlackCat (ALPHV) exposure... Shared wallet cluster receiving Embargo and BlackCat funds") providing on-chain forensic evidence supporting BlackCat-successor assessment beyond off-chain similarities alone.
(5) cluster-defining $34.2 million in incoming transaction volume per TRM Labs April 2024 - August 2025 + $13.5 million laundered via global VASPs distribution + signature sanctioned-platform Cryptex.net laundering tradecraft consistent with Russian-aligned cybercrime ecosystem.
(6) cluster-defining U.S. healthcare-focused victim targeting with multiple hospital + pharmacy victims at $1.3M ransom demand levels.
(7) signature U.S. municipal government + police-department attack with Town of Summerville SC 1.71 TB data theft October 2024.
(8) signature RaaS affiliate model with cut of proceeds operational framework.
cluster fills the April-2024-emergence- post-BlackCat-exit-scam + Rust-based-RaaS + suspected-BlackCat-ALPHV-successor + $34.2M- cryptocurrency-volume + U.S.-healthcare-focused- victims + on-chain-wallet-infrastructure-overlap + Cryptex.net-sanctioned-laundering + Town-of- Summerville-SC-police-1.71-TB + similar-BlackCat- leak-site-UI position in 2022-2025 post-takedown + emerging RaaS cell.
canonical illustration of April 2024 emerging RaaS + suspected-BlackCat- successor-operation + Rust-programming-language- lineage + on-chain wallet infrastructure overlap signature + U.S. healthcare-focused victim profile + sanctioned-platform laundering tradecraft cited in essentially all subsequent post-BlackCat industry analyses through 2024-2026 period.