embargo

Ransomware
Sourceransomware.live

About the group

Embargo is a Rust-based ransomware-as-a-service group that emerged in April 2024, primarily targeting US healthcare, manufacturing, and business services organizations using double extortion, assessed as a potential successor to BlackCat/ALPHV with over $34 million in ransom proceeds.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Impact and victims

The group embargo has 1 known ransomware victims. See the most affected sectors and countries and recent victims.

1known victims
1in Brazil
1sectors hit
Most attacked sectors
Technology1
Most affected countries
🇧🇷 Brasil1
Recent victims
tequaly.comTechnology · BR · 2025-02-20

embargo uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →