Skip to content

Embargo Ransomware Group Moved $34M in Crypto Since April, TRM Labs Reports

2025-08-10 18:49:49

Main Idea

The Embargo ransomware group has moved over $34 million in cryptocurrency since April 2024, targeting sectors like healthcare and using ransomware-as-a-service, with potential links to the BlackCat group.

Key Points

1. Embargo ransomware group has moved over $34 million in ransom-linked cryptocurrency since April 2024, operating under a ransomware-as-a-service (RaaS) model.

2. Confirmed victims include American Associated Pharmacies and Georgia-based entities, with ransom demands as high as $1.3 million per incident.

3. TRM Labs suggests Embargo could be a rebranded version of the BlackCat (ALPHV) group, which disappeared earlier this year.

4. Around $18.8 million of Embargo’s proceeds remain untouched in unaffiliated wallets, with laundering tactics involving intermediary wallets and high-risk exchanges.

5. Embargo employs double extortion tactics, targeting sectors where downtime is costly, particularly focusing on US-based victims for higher payment capacity.

Description

Embargo Ransomware Moves $34M in Crypto Since April A relatively new ransomware group known as Embargo has emerged as a significant threat in the cybercrime landscape, moving over $34 million in ransom-linked cryptocurrency since April 2024, according to blockchain intelligence firm TRM Labs. Operating under a ransomware-as-a-service (RaaS) model, Embargo has attacked critical infrastructure across the United States, including hospitals and pharmaceutical networks. Hospitals and Pharmaceutical N...

>> go to origin page

More Reading