Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
Embargo ransomware group moved $34M in crypto since April: TRM Labs

Embargo ransomware group moved $34M in crypto since April: TRM Labs

CryptoNewsNetCryptoNewsNet2025/08/10 11:05
By:cointelegraph.com

A relatively new ransomware group known as Embargo has become a key player in the cybercrime underground, moving over $34 million in crypto-linked ransom payments since April 2024.

Operating under a ransomware-as-a-service (RaaS) model, Embargo has hit critical infrastructure across the United States, with targets including hospitals and pharmaceutical networks, according to blockchain intelligence firm TRM Labs.

Victims include American Associated Pharmacies, Georgia-based Memorial Hospital and Manor, and Weiser Memorial Hospital in Idaho. Ransom demands have reportedly reached up to $1.3 million.

TRM's investigation suggests Embargo may be a rebranded version of the infamous BlackCat (ALPHV) operation, which disappeared following a suspected exit scam earlier this year. The two groups share technical overlap, using the Rust programming language, operating similar data leak sites, and exhibiting onchain ties through shared wallet infrastructure.

Embargo ransomware group moved $34M in crypto since April: TRM Labs image 0
TRM’s Graph Visualizer showing a small Embargo wallet cluster with incoming BlackCat (ALPHV) exposure. Source: TRM Labs

Related: US DOJ seizes $24M in crypto from accused Qakbot malware developer

Embargo holds $18.8M in dormant crypto

Around $18.8 million of Embargo’s crypto proceeds remain dormant in unaffiliated wallets, a tactic experts believe may be designed to delay detection or exploit better laundering conditions in the future.

The group uses a network of intermediary wallets, high-risk exchanges, and sanctioned platforms, including Cryptex.net, to obscure the origin of funds. From May through August, TRM traced at least $13.5 million across various virtual asset service providers and more than $1 million routed through Cryptex alone.

While not as visibly aggressive as LockBit or Cl0p, Embargo has adopted double extortion tactics, encrypting systems and threatening to leak sensitive data if victims fail to pay. In some instances, the group has publicly named individuals or leaked data on its site to increase pressure.

Embargo primarily targets sectors where downtime is costly, including healthcare, business services, and manufacturing, and has shown a preference for US-based victims, likely due to their higher capacity to pay.

Related: Coinbase faces $400M bill after insider phishing attack

UK to ban ransomware payments for public sector

The UK is set to ban ransomware payments for all public sector bodies and critical national infrastructure operators, including energy, healthcare, and local councils. The proposal introduces a prevention regime requiring victims outside the ban to report intended ransom payments.

The plan also includes a mandatory reporting system, with victims required to submit an initial report to the government within 72 hours of an attack and a detailed follow-up within 28 days.

Ransomware saw a 35% drop in attacks last year, according to Chainalysis. It marked the first drop in ransomware revenues since 2022, according to the report.

Magazine: Inside a 30,000 phone bot farm stealing crypto airdrops from real users

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

IoTeX launches the world's first on-chain identity solution ioID designed specifically for smart devices

ioID is revolutionizing identity management for smart devices, allowing DePIN to authenticate devices, protect data, and unlock next-generation application scenarios within a user-owned ecosystem compatible with any blockchain.

IoTeX社区2025/11/25 18:52
IoTeX launches the world's first on-chain identity solution ioID designed specifically for smart devices

Mars Morning News | Last week, global listed companies made a net purchase of $13.4 million in BTC, while Strategy did not buy any Bitcoin last week

Expectations for a Federal Reserve interest rate cut in December have risen, with Bitcoin briefly surpassing $89,000 and the Nasdaq surging 2.69%. There are internal disagreements within the Fed regarding rate cuts, causing a strong reaction in the cryptocurrency market. Summary generated by Mars AI. This summary is generated by the Mars AI model and its accuracy and completeness are still being iteratively updated.

MarsBit2025/11/25 18:41
Mars Morning News | Last week, global listed companies made a net purchase of $13.4 million in BTC, while Strategy did not buy any Bitcoin last week

The covert battle in the crypto industry escalates: 40% of job seekers are North Korean agents?

North Korean agents have infiltrated 15%-20% of crypto companies, and 30%-40% of job applications in the crypto industry may come from North Korean operatives. They act as proxies through remote work, using malware and social engineering to steal funds and manipulate infrastructure. North Korean hackers have stolen over $3 billion in cryptocurrency to fund nuclear weapons programs. Summary generated by Mars AI. This summary is generated by the Mars AI model, and its accuracy and completeness are still being iteratively improved.

MarsBit2025/11/25 18:40
The covert battle in the crypto industry escalates: 40% of job seekers are North Korean agents?

Which targets are Wall Street short sellers eyeing? Goldman Sachs reveals the short-selling undercurrents amid the AI wave

Data shows that short selling in the US stock market has reached a five-year high. However, investors are not recklessly challenging AI giants; instead, they are targeting so-called "pseudo-beneficiaries"—companies that have surged on the AI concept but lack core competitiveness.

深潮2025/11/25 17:27