EXECUTIVE SUMMARY:
Researchers have identified new Rust-based tools developed by the Embargo ransomware group to enhance the deployment and impact of its ransomware, observed in attacks targeting US companies. This ransomware, named Embargo, surfaced in quickly becoming a notable player for its cross-platform versatility achieved through Rust programming. The group has implemented a new loader, MDeployer, and a custom EDR-killer tool, MS4Killer, tailored per victim environment, and exploits Safe Mode to bypass security controls. These tools indicate continuous development, with different versions and bugs suggesting ongoing refinement. Embargo uses Rust not only for ransomware payloads but also for its specialized tooling, showcasing its commitment to leveraging robust and cross-platform-compatible solutions.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Researchers have identified new Rust-based tools developed by the Embargo ransomware group to enhance the deployment and impact of its ransomware, observed in attacks targeting US companies. This ransomware, named Embargo, surfaced in quickly becoming a notable player for its cross-platform versatility achieved through Rust programming. The group has implemented a new loader, MDeployer, and a custom EDR-killer tool, MS4Killer, tailored per victim environment, and exploits Safe Mode to bypass security controls. These tools indicate continuous development, with different versions and bugs suggesting ongoing refinement. Embargo uses Rust not only for ransomware payloads but also for its specialized tooling, showcasing its commitment to leveraging robust and cross-platform-compatible solutions.[emaillocker id="1283"]
The MDeployer loader is a key component in Embargo’s attack chain, decrypting and executing the MS4Killer EDR killer and the Embargo ransomware payload. MS4Killer utilizes the Bring Your Own Vulnerable Driver (BYOVD) technique to disable security solutions on infected systems by exploiting a vulnerable driver, probmon.sys, signed with a revoked certificate. MDeployer has shown signs of being under active development, with different versions deployed in the same attack, suggesting ongoing refinements. Notably, the group has also tailored its tools for individual victims, with customized versions of MDeployer and MS4Killer observed in attacks. The malware drops encrypted payloads and logs execution errors while employing Safe Mode to avoid detection by security tools.
The Embargo ransomware group represents a new in the ransomware landscape, leveraging modern, custom-written Rust-based tools and active development to bypass security measures and deploy ransomware. Their use of Safe Mode abuse, BYOVD, and tailored tool deployment demonstrates a high level of resourcefulness and adaptability, marking them as a significant threat in the ecosystem. The group’s rapid evolution and the continued development of its tools suggest that they will remain a prominent player in the ransomware.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Resource Development | T1587 | Develop Capabilities |
| Execution | T1059 | Command and Scripting Interpreter |
| T1053 | Scheduled Task/Job | |
| T1569 | System Services | |
| Persistence | T1547 | Boot or Logon Autostart Execution |
| T1136 | Create Account | |
| Defense Evasion | T1562 | Impair Defenses |
| T1070 | Indicator Removal | |
| T1112 | Modify Registry | |
| T1027 | Obfuscated Files or Information | |
| Discovery | T1135 | Network Share Discovery |
| T1083 | File and Directory Discovery | |
| Impact | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery |
REFERENCES:
The following reports contain further technical details:
https://www.welivesecurity.com/en/eset-research/embargo-ransomware-rocknrust/