Embargo, also tracked as Storm-0501 and G1053, is conducting double-extortion ransomware operations against organizations in technology, healthcare, manufacturing, and other sectors. The group steals data—frequently using Rclone to MEGA—before encrypting systems with ChaCha20 and Curve25519. Researchers assess it as a probable BlackCat/ALPHV successor or rebrand based on Rust-based tooling, leak-site similarities, timing, and reported cryptocurrency-wallet overlap, though direct organizational continuity remains unconfirmed. Its intrusion activity includes exploiting internet-facing vulnerabilities, purchasing or abusing credentials, compromising Active Directory, and using bring-your-own-vulnerable-driver techniques to terminate security products.
Microsoft reported that Storm-0501 has expanded beyond on-premises encryption into cloud-focused extortion by pivoting from Active Directory into Microsoft Entra ID and Azure. In one enterprise intrusion, the actor abused an Entra Connect Sync server and an MFA-less synchronized Global Administrator account, established federation-based persistence with AADInternals, exposed Azure Storage, and exfiltrated data with AzCopy. The group then sought to destroy cloud storage and backups by removing locks and immutability controls; where deletion was prevented, it used customer-managed keys and encryption scopes to render blobs inaccessible and attempted to delete the associated keys. Embargo also uses MDeployer and MS4Killer for persistence and defense evasion, including Safe Mode services, scheduled tasks, registry changes, and the vulnerable probmon.sys driver before disabling recovery and encrypting victims’ files.

TTPs, infrastructure, and targeting history in one profile.
9 events from the most recent confirmed update back to the earliest known activity.
Lagoon Amusement Park in the United States was identified as Embargo's most recent named leak-site victim. The operation had listed 38 named victims by this point.
Microsoft reported that Storm-0501 had extended its on-premises ransomware activity into hybrid-cloud environments, compromising Active Directory and pivoting into Microsoft Entra ID to gain Global Administrator privileges.
Embargo's first reported victim appeared on its leak site, marking the operation's first known public victim listing.
The Embargo ransomware-as-a-service operation, also tracked as Storm-0501 and G1053, was first observed.
BlackCat/ALPHV reportedly conducted an exit scam. Embargo later emerged as a suspected, though unconfirmed, successor or rebrand sharing tooling and infrastructure characteristics.
Storm-0501 used Embargo ransomware in its attacks during 2024.
Storm-0501 targeted organizations in the healthcare sector.
Storm-0501 deployed Sabbath ransomware in attacks targeting school districts in the United States.
In a recent campaign against a large enterprise, Storm-0501 pivoted from Active Directory into Entra ID and Azure, established a malicious federated-domain backdoor, exfiltrated Azure Storage data, and attempted to delete or encrypt cloud resources and backups before extorting the victim through Microsoft Teams.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
shroudcloud.io
Open sourceattack.mitre.org
Open sourcemicrosoft.com
Open sourcetrmlabs.com
Open sourcewelivesecurity.com
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.