Embargo Ransomware Group Amasses $34M Since April , TRM Labs Reports
TRM Labs has uncovered that the Embargo ransomware group, operating under a ransomware-as-a-service model, has generated $34 million since April 2024. The group has targeted critical U.S. infrastructure, including hospitals and pharmaceutical networks, with ransom demands exceeding $1.3 million.
Investigations suggest Embargo may be a rebranded version of the notorious BlackCat (ALPHV) operation, which vanished earlier this year after an exit scam. Technical overlaps, including the use of Rust programming language and shared wallet infrastructure, point to a potential connection between the two entities.
Approximately $18 million of Embargo's illicit proceeds remain dormant in unaffiliated wallets, a tactic believed to delay detection or await future exploit opportunities. The group leverages intermediary wallets, high-risk exchanges, and sanctioned platforms to obscure its activities.