Embargo Ransomware Gang
Threat Actor
Embargo is a ransomware operation known for using Rust-based malware and operating under a ransomware-as-a-service (Raas) model. Like many modern ransomware groups, Embargo employs double extortion tactics where they first exfiltrate sensitive data from their victims before encrypting their files. They then threaten to release the stolen data unless a ransom Is paid.
The group was first observed by researchers early 2024. Embargo has claimed attacks on multiple hospitals.
Incidents Associated with this Threat
- November 3, 2024: Georgia Hospital Under Cyberattack Unable to Access Record System
- October 2, 2024: Systems and Phones Down at Idaho Weiser Memorial Hospital
- April 1, 2024: Cyberattack at NorthBay Health
Malware Used by this Threat Actor
No malware identified for this threat actor.
