The Embargo ransomware group has stolen $34.2 million since emerging in April 2024, targeting victims across the healthcare, business services, and manufacturing.The Embargo ransomware group has stolen $34.2 million since emerging in April 2024, targeting victims across the healthcare, business services, and manufacturing.

Embargo ransomware group nets $34.2m within a year: TRM Labs

2025/08/11 03:00

The Embargo ransomware group has stolen $34.2 million since emerging in April 2024, targeting victims across the healthcare, business services, and manufacturing sectors, according to TRM Labs research.

Most victims are located in the U.S., with ransom demands reaching up to $1.3 million per attack.

The cybercrime group has hit major targets, including American Associated Pharmacies, Memorial Hospital and Manor in Georgia, and Weiser Memorial Hospital in Idaho.

TRM Labs identified approximately $18.8 million in victim funds that remain dormant in unattributed wallets.

BlackCat connection suspected

According to TRM Labs, Embargo may be a rebranded version of the defunct BlackCat (ALPHV) ransomware group, based on technical similarities and shared infrastructure.

Both groups use the Rust programming language and maintain nearly identical data leak site designs and functionality.

On-chain analysis revealed that historical BlackCat-linked addresses funneled cryptocurrency to wallet clusters associated with Embargo victims.

The connection suggests that Embargo’s operators may have inherited the BlackCat operation or evolved from it following its apparent exit scam in 2024.

Embargo operates under a ransomware-as-a-service model, providing tools to affiliates while retaining control over core operations and payment negotiations. This structure enables rapid scaling across multiple sectors and geographic regions.

Embargo ransomware’s use of sophisticated laundering methods

The organization uses sanctioned platforms such as Cryptex.net, high-risk exchanges, and intermediary wallets to launder stolen cryptocurrency.

Between May and August 2024, TRM Labs monitored approximately $13.5 million in deposits made through various virtual asset service providers, including more than $1 million routed through Cryptex.net.

Embargo avoids heavy reliance on cryptocurrency mixers, instead layering transactions across multiple addresses before depositing funds directly into exchanges.

The group was observed using the Wasabi mixer in limited instances, with only two identified deposits.

The ransomware operators deliberately park funds at various stages of the laundering process, likely to disrupt tracing patterns or wait for favorable conditions such as reduced media attention or lower network fees.

Embargo specifically targets healthcare organizations to maximize leverage through operational disruption.

Healthcare attacks can directly impact patient care, with potentially life-threatening consequences, and create pressure for quick ransom payments.

The group employs double extortion tactics—encrypting files while exfiltrating sensitive data. Victims face threats of data leaks or dark web sales if they refuse payment, compounding financial damage with reputational and regulatory consequences.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

The Channel Factories We’ve Been Waiting For

The Channel Factories We’ve Been Waiting For

The post The Channel Factories We’ve Been Waiting For appeared on BitcoinEthereumNews.com. Visions of future technology are often prescient about the broad strokes while flubbing the details. The tablets in “2001: A Space Odyssey” do indeed look like iPads, but you never see the astronauts paying for subscriptions or wasting hours on Candy Crush.  Channel factories are one vision that arose early in the history of the Lightning Network to address some challenges that Lightning has faced from the beginning. Despite having grown to become Bitcoin’s most successful layer-2 scaling solution, with instant and low-fee payments, Lightning’s scale is limited by its reliance on payment channels. Although Lightning shifts most transactions off-chain, each payment channel still requires an on-chain transaction to open and (usually) another to close. As adoption grows, pressure on the blockchain grows with it. The need for a more scalable approach to managing channels is clear. Channel factories were supposed to meet this need, but where are they? In 2025, subnetworks are emerging that revive the impetus of channel factories with some new details that vastly increase their potential. They are natively interoperable with Lightning and achieve greater scale by allowing a group of participants to open a shared multisig UTXO and create multiple bilateral channels, which reduces the number of on-chain transactions and improves capital efficiency. Achieving greater scale by reducing complexity, Ark and Spark perform the same function as traditional channel factories with new designs and additional capabilities based on shared UTXOs.  Channel Factories 101 Channel factories have been around since the inception of Lightning. A factory is a multiparty contract where multiple users (not just two, as in a Dryja-Poon channel) cooperatively lock funds in a single multisig UTXO. They can open, close and update channels off-chain without updating the blockchain for each operation. Only when participants leave or the factory dissolves is an on-chain transaction…
Share
BitcoinEthereumNews2025/09/18 00:09
SOLANA NETWORK Withstands 6 Tbps DDoS Without Downtime

SOLANA NETWORK Withstands 6 Tbps DDoS Without Downtime

The post SOLANA NETWORK Withstands 6 Tbps DDoS Without Downtime appeared on BitcoinEthereumNews.com. In a pivotal week for crypto infrastructure, the Solana network
Share
BitcoinEthereumNews2025/12/16 20:44
XRP ETFs pass $1 billion mark with no outflow days since launch

XRP ETFs pass $1 billion mark with no outflow days since launch

Markets Share Share this article
Copy linkX (Twitter)LinkedInFacebookEmail
XRP ETFs pass $1 billion mark with no outflo
Share
Coindesk2025/12/16 19:01