Memento, also known as Memento Team, is a financially motivated ransomware and extortion group documented in 2021. Its operations include exploiting CVE-2021-21972 in exposed VMware vCenter Server installations, stealing credentials, maintaining prolonged access, moving laterally, and exfiltrating data before deploying ransomware. In a documented intrusion, the group remained inside the victim network for more than five months and demanded approximately $1 million in Bitcoin while threatening to expose stolen data. The group uses Python-based ransomware packaged with PyInstaller. After endpoint protection disrupted an initial attempt to encrypt files directly, the operators modified their payloads to place victim files into password-protected WinRAR archives, encrypt the archive passwords, and delete the original files. This approach denied access to data while avoiding the direct file-encryption behavior detected by the victim's security controls. Memento's hands-on-keyboard operations use Impacket tools, including wmiexec and secretsdump, alongside Mimikatz for credential theft and Plink for SSH tunneling. Operators use compromised administrative accounts and RDP tunneled over SSH for lateral movement and manual ransomware deployment. Other observed techniques include scheduled-task persistence, network and storage reconnaissance, deployment of a Python keylogger, attempts to disable Microsoft Defender, deletion of RDP logs, and use of BCWipe to remove evidence and alter timestamps. Its ransom messaging imitated REvil's formatting and directed victims to communicate through Telegram.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Potentially related to a PowerShell reverse shell incident following VMware Horizon Log4Shell exploitation, but attribution is tentative.
Conducting hands-on-keyboard ransomware intrusions with long dwell time, exploiting exposed VMware vCenter Server, moving laterally via RDP, stealing credentials, exfiltrating data, and deploying a Python/PyInstaller ransomware that archives files into password-protected WinRAR archives instead of conventional file encryption.
Conducting ransomware and double-extortion attacks using a custom Python/PyInstaller payload that archives victim files into password-protected WinRAR archives, exfiltrates data, moves laterally via RDP, deploys keylogging, and evades detection by changing tactics after endpoint protection blocked direct encryption.
Ransomware operation potentially connected to Phosphorus through shared infrastructure, IOC overlaps, naming conventions, and similar TTPs.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.