ATT&CKReferencesCyble Embargo Ransomware May 2024

Cyble Embargo Ransomware May 2024

Cyble. (2024, May 24). The Rust Revolution: New Embargo Ransomware Steps In. Retrieved October 19, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareEmbargo

Embargo has obtained active services running on the victim’s system through the functions `OpenSCManagerW()` and `EnumServicesStatusExW()`.

T1057
Process Discovery
MalwareEmbargo

Embargo has utilized MS4Killer to detect running processes on the victim device. Embargo has also captured a snapshot of active running processes using the Windows API `CreateToolHelp32Snapshot()`.

T1083
File and Directory Discovery
MalwareEmbargo

Embargo has searched for folders, subfolders and other networked or mounted drives for follow on encryption actions. Embargo has also iterated device volumes using `FindFirstVolumeW()` and `FindNextVolumeW()` functions and then calls the `GetVolumePathNamesForVolumeNameW()` function to retrieve a list of drive letters and mounted folder paths for each specified volume.

T1106
Native API
MalwareEmbargo

Embargo has leveraged Windows Native API functions to execute its operations.

T1135
Network Share Discovery
MalwareEmbargo

Embargo has searched for folders, subfolders and other networked or mounted drives for follow-on encryption actions.

T1480.002
Mutual Exclusion
MalwareEmbargo

Embargo has utilized a hardcoded mutex name of “LoadUpOnGunsBringYourFriends” using the `CreateMutexW()` function. Embargo has also utilized a hardcoded mutex name of “IntoTheFloodAgainSameOldTrip."

T1486
Data Encrypted for Impact
MalwareEmbargo

Embargo has the ability to encrypt files with the ChaCha20 and Curve25519 cryptographic algorithms. Embargo also has the ability to encrypt system data and add a random six-letter extension consisting of hexadecimal characters such as ".b58eeb" or “.3d828a” to encrypted files.

T1489
Service Stop
MalwareEmbargo

Embargo has terminated active processes and services based on a hardcoded list using the `CloseServiceHandle()` function. Embargo has also leveraged MS4Killer to terminate processes contained in an embedded list of security software process names that were XOR-encrypted.

T1490
Inhibit System Recovery
MalwareEmbargo

Embargo has cleared files from the recycle bin by invoking `SHEmptyRecycleBinW()` and disabled Windows recovery through `C:\Windows\System32\cmd.exe /q /c bcdedit /set {default} recoveryenabled no`.

T1657
Financial Theft
MalwareEmbargo

Embargo has been leveraged in double-extortion ransomware, exfiltrating files then encrypting them, to prompt victims to pay a ransom.

T1679
Selective Exclusion
MalwareEmbargo

Embargo has avoided encrypting specific files and directories by leveraging a regular expression within the ransomware binary.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.