Embargo is a relatively new ransomware group that emerged in mid-2024, quickly gaining notoriety for its sophisticated
tactics and custom tools. Operating under a Ransomware-as-a-Service (RaaS) model, Embargo leverages Rust-based
malware to attack both Windows and Linux systems. The group’s hallmark is a defence-evasion toolkit that disables security
protections on victim machines, ensuring their ransomware can encrypt files without interference. Like many modern
groups, Embargo employs double extortion (stealing sensitive data before encryption), to pressure victims into paying
under threat of public leaks. Despite being a newcomer, Embargo is already considered a significant global threat, having
targeted organisations across sectors and caused serious disruptions.

Download this report

Further Threat Actor reports from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

Colorado, USA Office

950 S Cherry St Ste 505
Denver, Colorado
USA
80246

Colorado, USA Office

950 S Cherry St Ste 505
Denver, Colorado
USA
80246

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Arizona, USA Office

1300 S Litchfield Rd
110-L, Goodyear
USA
Arizona 85338

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

950 S Cherry St Ste 505
Denver, Colorado
USA
80246

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



COLORADO, USA OFFICE
950 S Cherry St Ste 505
Denver, Colorado
USA
80246


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content