Embargo ransomware: Rock’n’Rust
ID: 8bf2f53f-82f6-5073-a151-3782c8391e18
STIX ID: report--8bf2f53f-82f6-5073-a151-3782c8391e18
Feed Name: WeLiveSecurity (ESET Research)
Threat Score
ESET details an active ransomware campaign by the Embargo group that uses Rust-written tooling (MDeployer and MS4Killer) to disable endpoint security (via Safe Mode abuse and BYOVD with an embedded vulnerable driver) and deploy a Rust-based ransomware payload; the report provides technical analysis, observed behaviors, IoCs (hashes, file paths, commands, certificate), and MITRE ATT&CK mappings to support detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
