Defense Evasion
- s4killer (Minifilter Driver)
Embargo is a Rust-based ransomware family and ransomware-as-a-service operation, also tracked in some reporting as Storm-0501.
Profile source: Mallory opens in a new tabEmbargo
Embargo is a Rust-based ransomware family and ransomware-as-a-service operation, also tracked in some reporting as Storm-0501. First observed in 2024, it is associated with double-extortion intrusions in which operators exfiltrate victim data before encrypting systems to increase pressure for payment. Multiple assessments have linked the operation to the post-BlackCat/ALPHV ransomware ecosystem, and affiliate activity has been associated with financially motivated intrusion sets targeting higher-value organizations, including notable concentration in the United States and sectors such as technology and healthcare.
Embargo’s tooling commonly includes the MDeployer loader and the MS4Killer utility. MDeployer is used to decrypt and launch payloads, while MS4Killer is used to weaken endpoint protections and terminate targeted processes and services. A notable feature of Embargo operations is Safe Mode abuse for defense evasion and persistence: the malware has been observed modifying Windows configuration to ensure a malicious service launches after reboot in Safe Mode, allowing execution while many security products are inactive. It also establishes persistence through a scheduled task for the loader.
The ransomware supports extensive pre-encryption discovery and preparation. It enumerates processes, active services, device volumes, mounted and networked drives, and recursively searches folders and subfolders to identify encryption targets. It terminates selected processes and services, including security tooling, and has used a Bring Your Own Vulnerable Driver technique through MS4Killer to disable defenses at the kernel level. Additional anti-recovery behavior includes disabling Windows recovery features, clearing deleted-file artifacts, and removing temporary components after execution.
Embargo encrypts files using ChaCha20 with Curve25519 or X25519-based asymmetric key exchange and appends randomized hexadecimal extensions to encrypted files. It excludes selected files and directories from encryption through embedded filtering logic. Reported intrusion chains tied to Embargo affiliates include exploitation of known public-facing vulnerabilities, use of stolen credentials and access brokers, lateral movement with common post-exploitation frameworks and remote management tools, and data exfiltration to cloud storage services before ransomware deployment. The malware is therefore best characterized as a mature enterprise-targeting ransomware platform with strong defense-evasion, persistence, discovery, and extortion capabilities.
Reported operators
Embargo has obtained persistence of the loader MDeployer by creating a scheduled task named "Perf_sys."
Hastalamuerte was an experienced affiliate who had previously worked with Embargo, LockBit, and Medusa before joining Qilin.
Exploited software
MITRE ATT&CK
Reporting
Brazilian educational institutions faced a sustained wave of cyber incidents in incident-response cases reviewed from January 2025 through June 2026, with attackers most often gaining access through valid accounts, exploitation of public-facing applications, insider activity, and weak patch management. High-severity cases were dominated by ransomware, particularly DragonForce and LockBit 3, and private institutions were more frequently affected than public ones. Investigators also found that outdated and unpatched systems, including Windows 10 deployments kept past end of support and unpatched Windows Server 2016 hosts, materially increased exposure. Representative intrusions showed attackers relying on common but effective techniques rather than novel tradecraft. One LockBit case involved a custom deployment built from the leaked builder and spread with PsExec, aligning with the well-documented abuse of Windows service execution for lateral movement and payload launch. Another DragonForce intrusion used AnyDesk and log wiping to maintain access and hinder response, while a separate insider case involved a Python keylogger installed on a shared machine to capture credentials. The findings underscore the need for MFA, least privilege, removal of shared accounts, tighter control of remote-access tools, stronger backups, centralized logging, longer EDR retention, and faster patching.
SMAUG is a ransomware-as-a-service (RaaS) operation that advertises 64-bit payloads for Windows, Linux, and macOS, positioning itself as a multi-platform option for affiliates. The service reportedly charges a 20% affiliate fee plus a 0.2 BTC registration fee, and provides a web-based campaign builder, customizable ransom demands, offline encryption, and a "Company Mode" that allows a single decryption key to unlock multiple systems inside one targeted organization. Victims are directed to a Tor-based payment portal, while operators reportedly offer automated support for both affiliates and victims and bar attacks against CIS countries. On Windows, SMAUG uses obfuscated Go binaries that gather system details and stored browser credentials, establish persistence through Registry Run Keys consistent with MITRE ATT&CK T1547.001, and then encrypt files for impact using AES-256 with keys protected by RSA-2048, aligning with T1486 Data Encrypted for Impact tradecraft. The combination of credential collection, registry-based autostart, and hybrid cryptography reflects a mature ransomware model designed to support repeatable intrusions and broad enterprise targeting across multiple operating systems.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.