Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert
Zero fees, no slippage
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Embargo ransomware group moved $34M in crypto since April: TRM Labs

Embargo ransomware group moved $34M in crypto since April: TRM Labs

CryptoNewsNetCryptoNewsNet2025/08/10 11:05
By:cointelegraph.com

A relatively new ransomware group known as Embargo has become a key player in the cybercrime underground, moving over $34 million in crypto-linked ransom payments since April 2024.

Operating under a ransomware-as-a-service (RaaS) model, Embargo has hit critical infrastructure across the United States, with targets including hospitals and pharmaceutical networks, according to blockchain intelligence firm TRM Labs.

Victims include American Associated Pharmacies, Georgia-based Memorial Hospital and Manor, and Weiser Memorial Hospital in Idaho. Ransom demands have reportedly reached up to $1.3 million.

TRM's investigation suggests Embargo may be a rebranded version of the infamous BlackCat (ALPHV) operation, which disappeared following a suspected exit scam earlier this year. The two groups share technical overlap, using the Rust programming language, operating similar data leak sites, and exhibiting onchain ties through shared wallet infrastructure.

Embargo ransomware group moved $34M in crypto since April: TRM Labs image 0
TRM’s Graph Visualizer showing a small Embargo wallet cluster with incoming BlackCat (ALPHV) exposure. Source: TRM Labs

Related: US DOJ seizes $24M in crypto from accused Qakbot malware developer

Embargo holds $18.8M in dormant crypto

Around $18.8 million of Embargo’s crypto proceeds remain dormant in unaffiliated wallets, a tactic experts believe may be designed to delay detection or exploit better laundering conditions in the future.

The group uses a network of intermediary wallets, high-risk exchanges, and sanctioned platforms, including Cryptex.net, to obscure the origin of funds. From May through August, TRM traced at least $13.5 million across various virtual asset service providers and more than $1 million routed through Cryptex alone.

While not as visibly aggressive as LockBit or Cl0p, Embargo has adopted double extortion tactics, encrypting systems and threatening to leak sensitive data if victims fail to pay. In some instances, the group has publicly named individuals or leaked data on its site to increase pressure.

Embargo primarily targets sectors where downtime is costly, including healthcare, business services, and manufacturing, and has shown a preference for US-based victims, likely due to their higher capacity to pay.

Related: Coinbase faces $400M bill after insider phishing attack

UK to ban ransomware payments for public sector

The UK is set to ban ransomware payments for all public sector bodies and critical national infrastructure operators, including energy, healthcare, and local councils. The proposal introduces a prevention regime requiring victims outside the ban to report intended ransom payments.

The plan also includes a mandatory reporting system, with victims required to submit an initial report to the government within 72 hours of an attack and a detailed follow-up within 28 days.

Ransomware saw a 35% drop in attacks last year, according to Chainalysis. It marked the first drop in ransomware revenues since 2022, according to the report.

Magazine: Inside a 30,000 phone bot farm stealing crypto airdrops from real users

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

MetaMask: Bridging Web2 Simplicity with Web3 Security

- MetaMask launched a Social Login feature, enabling users to access crypto wallets via Google or Apple accounts, simplifying traditional 12-word recovery phrase management. - The system generates and stores recovery phrases locally, requiring both social credentials and a user-created password for access, preserving self-custody principles. - Users retain full password recovery responsibility, while MetaMask also announced a stablecoin (mUSD) to enhance DeFi accessibility without compromising security. -

ainvest2025/08/27 23:39
MetaMask: Bridging Web2 Simplicity with Web3 Security

Nvidia Defies China Restrictions, But AI’s Future Remains Uncertain

- Nvidia reported a 56% YoY revenue surge to $46.7B in Q2, exceeding forecasts despite China H20 chip restrictions. - China's AI chip self-reliance plans and U.S. export controls threaten long-term market share, though B30A chip approval is pending. - Wall Street remains bullish with 13/14 analysts rating "buy," but warns of AI market sustainability risks and concentration in cloud providers. - The company diversifies into automotive/robotics and approved $60B stock buybacks to mitigate data center depende

ainvest2025/08/27 23:39
Nvidia Defies China Restrictions, But AI’s Future Remains Uncertain

XRP News Today: Regulatory Clarity Paves the Road for XRP’s Institutional Takeoff

- BNB hits $846.89 all-time high, signaling broader altcoin market momentum amid growing institutional interest in crypto assets. - XRP gains 6% post-legal victory as U.S. court ruled XRP not a security, clearing regulatory hurdles for ETF approvals in October 2025. - Analysts highlight XRP's potential to $5.25 by 2030, driven by improved liquidity and regulatory clarity, though competition from stablecoins and CBDCs remains. - Technical analysis shows XRP consolidating in bullish patterns, with key resist

ainvest2025/08/27 23:39
XRP News Today: Regulatory Clarity Paves the Road for XRP’s Institutional Takeoff

Aave Bridges TradFi and DeFi with $26B RWA Lending Leap

- Aave Labs launched Horizon, enabling institutions to borrow stablecoins using tokenized real-world assets (RWAs) as collateral on Aave V3. - The platform integrates Chainlink’s NAVLink for real-time asset valuations and combines compliance features with permissionless liquidity pools. - Partners like Centrifuge and Circle provide tokenized U.S. Treasuries and CLOs, expanding access to $26B+ RWA markets dominated by Ethereum. - Horizon bridges TradFi and DeFi by offering 24/7 institutional-grade lending,

ainvest2025/08/27 23:39
Aave Bridges TradFi and DeFi with $26B RWA Lending Leap