• Trending
  • Comments
  • Latest
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated On 07/23/2025
FBI nabs Nigerian ‘tech queen’ Sapphire Egemasi in multi-million dollar fraud scheme

FBI arrests Nigerian ‘tech queen’ Sapphire Egemasi in $1.3M heist targeting U.S. government

06/05/2025 - Updated On 06/17/2025
Deutsche Bank eyes stablecoin launch as tokenization wave hits European banking

Deutsche Bank eyes stablecoin launch as tokenization wave hits European banking

06/09/2025 - Updated On 07/07/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
SHIB, DOGE slump drives investors toward Layer Brett in 2025 shift

SHIB, DOGE slump drives investors toward Layer Brett in 2025 shift

08/16/2025
The Core of Senator Lummis Bitcoin Plan

Senator Lummis unveils bold Bitcoin plan to cement U.S. crypto dominance

08/16/2025
Crypto bank fees sparks showdown between banks and industry; Trump pressed to intervene

Banks clash with crypto industry over fees as Trump faces pressure to act

08/16/2025
  • Trending
  • Comments
  • Latest
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated On 07/23/2025
FBI nabs Nigerian ‘tech queen’ Sapphire Egemasi in multi-million dollar fraud scheme

FBI arrests Nigerian ‘tech queen’ Sapphire Egemasi in $1.3M heist targeting U.S. government

06/05/2025 - Updated On 06/17/2025
Deutsche Bank eyes stablecoin launch as tokenization wave hits European banking

Deutsche Bank eyes stablecoin launch as tokenization wave hits European banking

06/09/2025 - Updated On 07/07/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
SHIB, DOGE slump drives investors toward Layer Brett in 2025 shift

SHIB, DOGE slump drives investors toward Layer Brett in 2025 shift

08/16/2025
The Core of Senator Lummis Bitcoin Plan

Senator Lummis unveils bold Bitcoin plan to cement U.S. crypto dominance

08/16/2025
Crypto bank fees sparks showdown between banks and industry; Trump pressed to intervene

Banks clash with crypto industry over fees as Trump faces pressure to act

08/16/2025
Saturday, August 16, 2025
  • Login
The Bit Gazette
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Contact
No Result
View All Result
The Bit Gazette
No Result
View All Result
Home Crypto News

TRM Labs: BlackCat linked group, Embargo laundered $34M from ransomware hospital crypto attacks

TRM Labs links the Embargo ransomware group to the defunct BlackCat operation as ransomware hospital crypto attacks surge in sophistication and scale.

by Victor Johnson
5 days ago
in Crypto News
Reading Time: 2 mins read
0
TRM Labs: Embargo laundered $34M from hospital ransomware crypto attacks

TRM Labs: Embargo laundered $34M from hospital ransomware crypto attacks

Share on FacebookShare on Twitter

A new ransomware group known as Embargo has laundered over $34 million in cryptocurrency from a series of ransomware hospital crypto attacks across the United States, according to blockchain intelligence firm TRM Labs. Believed to be a rebrand of the defunct BlackCat operation, the gang has demanded ransoms of up to $1.3 million, using AI-enhanced tactics to breach systems, encrypt data, and extort victims.

TRM Labs research indicates that Embargo may be a rebrand of the now-defunct BlackCat operation, with high profile ransomware hospital crypto attacks hitting American Associated Pharmacies, Memorial Hospital and Manor in Georgia, and Weiser Memorial Hospital in Idaho.

Sophisticated RaaS Model Evades Detection

Operating under a Ransomware as a Service model, Embargo supplies affiliates with powerful attack tools while maintaining centralized control over infrastructure and ransom negotiations.

TRM’s Graph Visualizer showing a small Embargo wallet cluster with incoming BlackCat (ALPHV) exposure. Source: TRMLabs

Unlike LockBit or Cl0p, the group avoids flashy branding, which may help it evade law enforcement while expanding ransomware hospital crypto attacks into healthcare, manufacturing and business services.

Possible BlackCat Connection

Investigators found multiple technical overlaps between Embargo and BlackCat, including the Rust programming language, near identical leak site designs and shared wallet infrastructure.

Source: TRMLabs

Historical BlackCat linked wallets have transferred funds to addresses connected to ransomware hospital crypto attacks carried out by Embargo, suggesting operational continuity.

AI-Driven Cybercrime Surge

The rise of Embargo comes amid a broader surge in cybercrime. In July 2025 alone, crypto hack losses climbed 27.2% to $142 million, while the first half of 2025 saw $2.2 billion lost across 344 incidents.

Embargo leverages AI and machine learning to automate ransomware hospital crypto attacks, exploiting unpatched vulnerabilities, launching AI-generated phishing campaigns, and using malicious drive-by downloads.

Once inside networks, the group deploys a two-stage toolkit that disables defenses, deletes recovery options, encrypts files and exfiltrates sensitive data. This “double extortion” method pressures hospitals by threatening to leak or sell stolen patient records on the dark web.

Political and Financial Motives

Some ransomware hospital crypto attacks carried out by Embargo include politically charged messaging, hinting at potential state affiliations. This combination of ideological and financial motives complicates attribution and follows a trend of financially driven actors adopting political narratives.

Complex Laundering Networks

Embargo launders its ransom proceeds through intricate networks of intermediary wallets, high risk exchanges, and sanctioned platforms such as Cryptex.net.

Embargo deposits to Cryptnex.net Source: TRMLabs

TRM Labs traced $13.5 million through various exchanges, with 17 deposits exceeding $1 million sent via Cryptex.net between May and August 2024.

In total, around $18.8 million linked to ransomware hospital crypto attacks remains idle in unknown wallets possibly as part of evasion tactics or internal disputes within the group.

Other recent crypto security incidents include the $44.2 million breach at Indian exchange CoinDCX, tied to North Korea’s Lazarus Group, and a GreedyBear campaign using 150 weaponized Firefox extensions to steal over $1 million.

Tags: $34M stolenBitcoin tracingblockchain forensicscrypto crimecrypto launderingcybersecurity threatsdarknet marketsEmbargo ransomwarehacker fundshealthcare cybersecurityhospital cyberattackslaw enforcement cryptolockbit ransomware gangransomware paymentsTRM Labs
Share198Tweet124
Victor Johnson

Victor Johnson

Victor Prince Johnson a tech writer and crypto blogger with a passion for breaking down complex topics into clear, engaging, and accessible content. With a sharp eye on emerging technologies and the ever-evolving world of blockchain and digital finance, I aim to bridge the gap between innovation and everyday understanding. My content explores everything from AI and cybersecurity to Bitcoin trends, DeFi, NFTs, and the broader impact of tech on society. Whether you’re a tech enthusiast, crypto investor, or simply curious about where the digital world is headed, you’ll find insights, news, and thought-provoking analysis right here. Do follow me on this site as we explore the future, one post at a time.

  • Trending
  • Comments
  • Latest
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated On 07/23/2025
FBI nabs Nigerian ‘tech queen’ Sapphire Egemasi in multi-million dollar fraud scheme

FBI arrests Nigerian ‘tech queen’ Sapphire Egemasi in $1.3M heist targeting U.S. government

06/05/2025 - Updated On 06/17/2025
Deutsche Bank eyes stablecoin launch as tokenization wave hits European banking

Deutsche Bank eyes stablecoin launch as tokenization wave hits European banking

06/09/2025 - Updated On 07/07/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
SHIB, DOGE slump drives investors toward Layer Brett in 2025 shift

SHIB, DOGE slump drives investors toward Layer Brett in 2025 shift

08/16/2025
The Core of Senator Lummis Bitcoin Plan

Senator Lummis unveils bold Bitcoin plan to cement U.S. crypto dominance

08/16/2025
Crypto bank fees sparks showdown between banks and industry; Trump pressed to intervene

Banks clash with crypto industry over fees as Trump faces pressure to act

08/16/2025
The Bit Gazette

Copyright © 2025 - The Bit Gazette.

Navigate Site

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Follow Us

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Contact

Copyright © 2025 - The Bit Gazette.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?