Embargo on Ransomware Group Responsible for $34M Crypto Theft May Be Rebranding of Infamous BlackCat
BlackCat with a New Name? Ransomware Group Likely Changed Name to Embargo, TRM Says
Approximately $13 million has entered VASPs globally, while $18.8 million remains in non-attributed wallets – presumably due to slower detection and the wait for more favorable conditions to move funds.
Shaurya Malwa | Modified by Parikshit Mishra Updated August 11, 2025 12:45 PM Published August 11, 2025 12:32 PM

What you need to know:
- The Embargo ransomware group has made over $34 million since April 2024, possibly changing its name from the defunct BlackCat project.
- The group targets US economic sectors such as healthcare and manufacturing, demanding ransoms of up to $1.3 million.
- Embargo employs double extortion tactics and may use AI to improve phishing and reconnaissance operations.
Since its emergence in April 2024, the Embargo ransomware group has raised at least $34.2 million in various tokens, according to TRM Labs.
A blockchain analytics firm says similarities in the ransomware group's code and infrastructure indicate it is likely a rebranding of the shuttered BlackCat (ALPHV) operation.