Home/Threat Actor/Embargo
Threat Actor

Embargo

embargo_ransomware · ransomware_raas_suspected_blackcat_alphv_successor · active since 2024-04

Embargo (canonical naming) is a Rust-based Ransomware-as-a-Service (RaaS) operation emerging around April 2024 with significant operational + technical + on-chain similarities to BlackCat (ALPHV) which conducted apparent March 2024 exit scam following Change Healthcare $22 million ransom payment per IBM X-Force November 2025 context analysis ("In March 2024, BlackCat successfully compromised Change Healthcare and received a ransom payment of USD 22 million in Bitcoin. But here's where things get weird: Immediately after taking payment, BlackCat closed its doors, citing 'the feds' as the reason for the shutdown"); suspected BlackCat/ALPHV successor attribution via TRM Labs canonical August 2025 Unmasking Embargo Ransomware Deep Dive analysis ("TRM assesses that Embargo may be a rebrand or successor to BlackCat, also known as ALPHV, based on both on-chain and off-chain similarities. Technical overlaps include the use of the Rust programming language, a similarly designed data leak site, and on-chain overlaps via shared wallet infrastructure") + The Record / Recorded Future News + Cyble researchers leak site + UI + Rust variant similarities documentation + SC Media October 2024 Summerville SC coverage + GridInSoft canonical ALPHV Reborn analysis with honest attribution caveat that BlackCat-successor assessment is moderate-confidence per TRM Labs and group has not publicly claimed or denied lineage.

standalone cluster paralleling hunters_international + cactus + trigona in v0.1.160 2022-2025 post-takedown + emerging RaaS cell; operational target profile United States primary geographic per TRM Labs + signature U.S. healthcare- focused victim targeting (American Associated Pharmacies + Memorial Hospital and Manor in Georgia + Weiser Memorial Hospital in Idaho with ransom demands reaching $1.3 million) + business services + manufacturing secondary sectors + signature U.S. municipal government attack (Town of Summerville South Carolina with 1.71 TB stolen from police department October 2024)

operational attack architecture: (1) cluster-defining April 2024 emergence post-BlackCat March 2024 exit scam timing establishing successor-operation timing pattern.

(2) cluster-defining Rust programming language matching BlackCat tradecraft with Rust adopted for detection evasion + parallelism + cross-platform compatibility consistent with BlackCat-pioneered Rust ransomware tradecraft.

(3) cluster-defining similar leak site design + user interface to BlackCat per Cyble researchers indicating shared- design-team or shared-codebase signature.

(4) cluster-defining on-chain wallet infrastructure overlap with BlackCat funds per TRM Labs Graph Visualizer evidence ("TRM's Graph Visualizer showing a small Embargo wallet cluster with incoming BlackCat (ALPHV) exposure... Shared wallet cluster receiving Embargo and BlackCat funds") providing on-chain forensic evidence supporting BlackCat-successor assessment beyond off-chain similarities alone.

(5) cluster-defining $34.2 million in incoming transaction volume per TRM Labs April 2024 - August 2025 + $13.5 million laundered via global VASPs distribution + signature sanctioned-platform Cryptex.net laundering tradecraft consistent with Russian-aligned cybercrime ecosystem.

(6) cluster-defining U.S. healthcare-focused victim targeting with multiple hospital + pharmacy victims at $1.3M ransom demand levels.

(7) signature U.S. municipal government + police-department attack with Town of Summerville SC 1.71 TB data theft October 2024.

(8) signature RaaS affiliate model with cut of proceeds operational framework.

cluster fills the April-2024-emergence- post-BlackCat-exit-scam + Rust-based-RaaS + suspected-BlackCat-ALPHV-successor + $34.2M- cryptocurrency-volume + U.S.-healthcare-focused- victims + on-chain-wallet-infrastructure-overlap + Cryptex.net-sanctioned-laundering + Town-of- Summerville-SC-police-1.71-TB + similar-BlackCat- leak-site-UI position in 2022-2025 post-takedown + emerging RaaS cell.

canonical illustration of April 2024 emerging RaaS + suspected-BlackCat- successor-operation + Rust-programming-language- lineage + on-chain wallet infrastructure overlap signature + U.S. healthcare-focused victim profile + sanctioned-platform laundering tradecraft cited in essentially all subsequent post-BlackCat industry analyses through 2024-2026 period.

ransomware_raas_suspected_blackcat_alphv_successor confidence: high 14 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited0

Profile

Embargo (canonical naming) is a Rust-based Ransomware-as-a-Service (RaaS) operation emerging around April 2024 with significant operational + technical + on-chain similarities to BlackCat (ALPHV) which conducted apparent March 2024 exit scam following Change Healthcare $22 million ransom payment. TRM Labs August 2025 assessment that Embargo may be a rebranded or successor operation. Suspected BlackCat/ALPHV successor attribution via TRM Labs canonical August 2025 analysis with both on-chain and off-chain similarities + The Record / Recorded Future News + Cyble researchers + SC Media + GridInSoft industry coverage + IBM X-Force November 2025 context analysis. Honest attribution caveat: BlackCat-successor assessment is moderate- confidence per TRM Labs.

group has not publicly claimed or denied lineage. Standalone cluster paralleling hunters_international + cactus + trigona in v0.1.160 2022-2025 post- takedown + emerging RaaS cell.

Operational target profile
  • United States primary geographic per TRM Labs.
  • Healthcare signature primary sector (American Associated Pharmacies + Memorial Hospital Georgia + Weiser Memorial Hospital Idaho)
  • Business services + manufacturing secondary sectors.
  • U.S. municipal government signature (Town of Summerville SC + police 1.71 TB October 2024)
  • Ransom demands reaching $1.3M.
  • ~$34.2M cryptocurrency volume April 2024.
  • August 2025 Operational attack architecture: (1) April 2024 emergence post-BlackCat exit scam (cluster-defining): emergence timing immediately post-March 2024 BlackCat shutdown following Change Healthcare $22M ransom (2) Rust programming language matching BlackCat (cluster-defining): Rust tradecraft lineage signature (3) Similar leak site design + UI to BlackCat (cluster-defining): per Cyble researchers (4) On-chain wallet infrastructure overlap with BlackCat funds (cluster-defining): per TRM Labs Graph Visualizer evidence (5) $34.2M cryptocurrency volume + sanctioned Cryptex.net laundering (cluster-defining): per TRM Labs (6) U.S. healthcare-focused victim targeting (cluster-defining): signature primary sector (7) $13.5M VASP laundering distribution (signature): hundreds of deposits across multiple virtual asset service providers (8) Town of Summerville SC police 1.71 TB (signature): U.S. municipal government + police attack signature The cluster fills the April-2024-emergence-post- BlackCat-exit-scam + Rust-based-RaaS + suspected- BlackCat-ALPHV-successor + $34.2M-cryptocurrency- volume + U.S.-healthcare-focused-victims + on- chain-wallet-infrastructure-overlap + Cryptex.net- sanctioned-laundering position in 2022-2025 post- takedown + emerging RaaS cell.

Aliases

14
embargo_ransomwareembargoembargo ransomware-as-a-service raasembargo rust based ransomwareembargo blackcat alphv successor suspected april 2024embargo trm labs $34.2 million cryptocurrency volumeembargo american associated pharmacies victimembargo memorial hospital manor georgia weiser memorial hospital idahoembargo town of summerville south carolina police 1.71 tbembargo on-chain wallet overlap blackcat shared infrastructureembargo change healthcare blackcat 22 million exit scam march 2024embargo rebrand or successor operation blackcat alphvembargo cyble researchers leak site design similaritiesembargo us healthcare business services manufacturing

Notable Campaigns

9
2024-2026Continued Industry Reference Status (2024-2026)
2024-2025Embargo BlackCat/ALPHV Successor Assessment Signature (TRM Labs August 2025)
2024-2025Embargo Rust Programming Language Matching BlackCat Tradecraft Signature
2024-2025Embargo $34.2 Million Cryptocurrency Volume per TRM Labs August 2025
2024-2025Embargo On-Chain Wallet Infrastructure Overlap with BlackCat Signature
2024-2025Embargo Cryptex.net Sanctioned Platform Laundering Signature
2024Embargo Origin, April 2024 Emergence Post-BlackCat March 2024 Exit Scam
2024Embargo U.S. Healthcare-Focused Victims Signature
2024Embargo Town of Summerville South Carolina Police Attack, 1.71 TB (October 2024)

Attribution & Reporting

Attributed by
TRM Labs (canonical August 2025 Unmasking Embargo Ransomware Deep Dive analysis + $34.2M cryptocurrency volume + on-chain BlackCat-overlap)The Record / Recorded Future News (canonical August 2025 Embargo ransomware gang $34M coverage)Cyble (canonical leak site + UI + Rust variant similarities researchers)SC Media / CyberNews (canonical October 2024 ALPHV/BlackCat successor + Summerville SC police 1.71 TB coverage)GridInSoft (canonical New Embargo Ransomware Discovered Possible ALPHV Reborn analysis)IBM X-Force (canonical November 2025 Has BlackCat returned as Cicada3301 analysis + Change Healthcare $22M context)
Key reporting
reportTRM Labs: Unmasking Embargo Ransomware, A Deep Dive Into the Group's TTPs and BlackCat Links (August 2025), canonical $34.2M cryptocurrency volume + on-chain BlackCat overlap analysis
reportThe Record / Recorded Future News: Embargo ransomware gang has handled at least $34 million in about a year (August 2025)
reportSC Media / CyberNews: Suspected ALPHV/BlackCat successor sets sights on South Carolina town police (October 2024)
reportIBM X-Force: Has BlackCat returned as Cicada3301? Maybe. (November 2025), canonical Change Healthcare $22M context + BlackCat exit scam analysis
reportGridInSoft / Stephanie Adlam: canonical New Embargo Ransomware Discovered Possible ALPHV Reborn coverage
reportCyble researchers: canonical leak site design + UI + Rust variant similarities documentation

Operational

State sponsor

Independent Ransomware-as-a-Service (RaaS) operation assessed by TRM Labs + Cyble + The Record / Recorded Future News as suspected rebranded or successor operation to BlackCat (ALPHV). BlackCat conducted apparent exit scam in March 2024 after Change Healthcare $22 million ransom payment, with affiliates reporting administrators kept all proceeds. Embargo emerged just weeks after BlackCat shutdown.

Russian-aligned cybercrime ecosystem attribution consistent with BlackCat lineage. Honest attribution caveat: BlackCat-successor assessment is moderate-confidence per TRM Labs; group has not publicly claimed or denied lineage. Attribution chain: (1) TRM Labs canonical August 2025 BlackCat- successor assessment: per TRM Labs: "TRM assesses that Embargo may be a rebranded or evolved successor to BlackCat, which likely conducted an exit scam in 2024, based on the following off-chain similarities: Both groups use the Rust programming language...

TRM assesses that Embargo may be a rebrand or successor to BlackCat (also known as ALPHV), based on both on-chain and off-chain similarities. Technical overlaps include the use of the [Rust programming language, similarly designed data leak site, and on-chain overlaps via shared wallet infrastructure]." (2) TRM Labs $34.2M cryptocurrency volume quantification: per TRM Labs: "Since emerging around April 2024, ransomware-as-a-service (RaaS) group Embargo has established itself as a significant threat in the cybercrime landscape. TRM Labs has identified approximately USD 34.2 million in incoming transaction volume likely associated with the group, with most victims located in the United States (US) in the healthcare, business services, and manufacturing sectors." (3) The Record / Recorded Future News canonical August 2025 BlackCat-successor coverage: per The Record: "A cybercrime group that could be a successor to the BlackCat/Alphv ransomware operation is associated with about $34.2 million in cryptocurrency transactions since popping up in mid-2024...

Embargo started to draw scrutiny in late 2024, just a few months after BlackCat's leaders appeared to conduct an exit scam on affiliates... Echoing other companies, TRM said the gang 'may be a rebranded or successor operation to BlackCat (ALPHV) based on multiple technical and behavioral similarities,' including the infrastructure of its crypto wallets." (4) Cyble researchers leak site + UI + Rust variant similarities: per SC Media: "Embargo has been believed to be a rebrand of the ALPHV/BlackCat operation following Cyble researchers' discovery of similarities between both groups, including their site design and user interface, as well as their ransomware variants, both of which were found to be based on the Rust" programming language. (5) BlackCat exit scam context per IBM X-Force: per IBM X-Force November 2025: "In March 2024, BlackCat successfully compromised Change Healthcare and received a ransom payment of USD 22 million in Bitcoin.

But here's where things get weird: Immediately after taking payment, BlackCat closed its doors, citing 'the feds' as the reason for the shutdown... The group itself claimed law enforcement interference as the reason for the shutdown, but BlackCat affiliates told a different story: ALPHV administrators didn't share the profits of the Change Healthcare attack as promised, instead keeping everything for themselves." (6) GridInSoft canonical Embargo + ALPHV-reborn coverage: per GridInSoft: "New Embargo Ransomware Discovered, Possible ALPHV Reborn... A new strain of ransomware, named Embargo, written in Rust, recently surfaced." Industry consensus around BlackCat-successor characterization.

Operational mission objective: Financially-motivated RaaS double-extortion operation with cryptocurrency-focused monetization via global VASPs + sanctioned platforms (Cryptex. net) + mixing services + P2P marketplaces. Healthcare sector focus signature.

Operational target profile
  • United States primary geographic per TRM Labs.
  • Healthcare signature primary sector (American Associated Pharmacies + Memorial Hospital and Manor Georgia + Weiser Memorial Hospital Idaho)
  • Business services secondary sector.
  • Manufacturing secondary sector.
  • U.S. municipal government signature (Town of Summerville SC + police department 1.71 TB October 2024)
  • Ransom demands reaching $1.
3 million per TRM Labs Notable victim
  • American Associated Pharmacies, healthcare.
  • Memorial Hospital and Manor in Georgia, healthcare.
  • Weiser Memorial Hospital in Idaho, healthcare.
  • Town of Summerville (South Carolina) Police Department, 1.71 TB stolen October 2024.
  • Approximately $34.2 million cryptocurrency volume April 2024.
  • August 2025 per TRM Labs The cluster fills the April-2024-emergence-post- BlackCat-exit-scam + Rust-based-RaaS + suspected- BlackCat-ALPHV-successor + $34.2M-cryptocurrency- volume + U.S.-healthcare-focused-victims + on- chain-wallet-infrastructure-overlap + Cryptex.net- sanctioned-laundering position in 2022-2025 post- takedown + emerging RaaS cell.
Motivations
financially_motivated_ransomware_as_a_service_double_extortion, suspected_blackcat_alphv_successor_operation_capability, rust_based_ransomware_signature_capability, u_s_healthcare_focused_targeting_signature, cryptocurrency_focused_monetization_via_sanctioned_platforms_signature
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)58/60 · 96%
Analytics (MITRE CAR)35/60 · 58%
Runtime / container (Falco)9/60 · 15%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)19/60 · 31%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MIXING SERVICES + PEER-TO-PEER MARKETPLACES + NON-CUSTODIAL HIGH-RISK EXCHANGESSHARED WALLET CLUSTER RECEIVING EMBARGO AND BLACKCAT FUNDS TRM GRAPH VISUALIZER
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin