MDeployer is a Rust-based malicious loader used in Embargo ransomware intrusions. Public reporting cited in the provided content states that Embargo used MDeployer to execute the attack chain leading to ransomware deployment, including decrypting and launching two RC4-encrypted payloads: the MS4Killer EDR-killing toolkit (noted as b.cache) and the Embargo ransomware executable (a.cache). MDeployer has been associated with persistence via a DLL variant that installs a Windows service named irnagentd configured to launch after reboot in Safe Mode, and Embargo also used a scheduled task named Perf_sys to maintain persistence for the loader. The content further states that MDeployer was used to disable security solutions through Safe Mode, and that Embargo modified and deleted Registry keys and used BAT scripts to weaken defenses such as Windows Defender. Reported hardcoded mutexes associated with this tooling include LoadUpOnGunsBringYourFriends and IntoTheFloodAgainSameOldTrip. After execution, MDeployer was also reported to terminate the MS4Killer process, delete decrypted payload files and a dropped driver file, and reboot the system. MDeployer is specifically associated with the Embargo ransomware operation, which emerged in 2024 and has been assessed in the cited reporting as a ransomware-as-a-service operation and probable successor or rebrand of BlackCat/ALPHV. The surrounding Embargo campaigns targeted Windows environments and were observed across sectors including technology and healthcare, with a notable concentration of victims in the United States.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Entire toolchain written in Rust - ransomware, loader (MDeployer), and EDR killer (MS4Killer).
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Embargo has obtained persistence of the loader MDeployer by creating a scheduled task named "Perf_sys."
Embargo has obtained persistence of the loader MDeployer by creating a scheduled task named "Perf_sys."
Embargo has encrypted both MDeployer and MS4 Killer payloads with RC4.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Rust-written loader used in Embargo intrusions to decrypt and launch payload components from .cache files, including the ransomware and MS4Killer. A DLL variant can force Safe Mode reboot, establish persistence, tamper with Defender Safe Mode registry entries, and then execute the ransomware.
Loader/toolkit used to decrypt and launch payloads including MS4Killer and the Embargo ransomware executable, and to establish persistence via services and scheduled tasks, including Safe Mode execution.
Rust-based loader used in Embargo ransomware attacks to deploy/execute additional tooling or payloads.
Rust-based loader used in Embargo ransomware attacks to deploy/execute additional tooling or payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.