Memento is Windows ransomware used by the Memento Team operation and publicly identified in late 2021. Its payloads are Python 3.9 programs packaged with PyInstaller. An initial variant archived victim files and attempted direct encryption using AES-CBC, with RSA protecting per-file passwords. After endpoint protection blocked this approach, the operators revised the malware to place files into individual password-protected archives using a renamed legitimate WinRAR utility, encrypt the archive passwords, and delete the original files. This approach denied access to data while avoiding the direct file-encryption behavior detected by anti-ransomware protection.
The ransomware generates a victim identifier, collects system information, and transmits host details and execution telemetry to command-and-control infrastructure. Revised variants support command-line arguments and configurable processing exclusions.
Memento Team compromised an enterprise network through exploitation of CVE-2021-21972 in VMware vCenter Server and maintained access for several months before deploying ransomware in October 2021. The operators used credential-dumping tools, a separate Python keylogger, reconnaissance utilities, scheduled tasks, and RDP tunneled over SSH. They manually distributed the ransomware using stolen credentials and RDP, exfiltrated data before deployment, and threatened to publish stolen information alongside a ransom demand of approximately $1 million. The victim recovered most data from backups; captured archive passwords also enabled recovery of some affected files.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Memento attackers reportedly gained access to the victim's network in April 2021 by exploiting CVE-2021-21972, then remained for more than five months before exfiltrating data and deploying ransomware. | Memento is a Python-based ransomware used by the Memento group. The first Memento variant simply encrypts files in the compromised machine.
"The activity of Phosphorus with regard to ProxyShell took place in about the same time frame as Memento," the Cybereason Nocturnus Team said.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Memento is a Python-based ransomware used by the Memento group. The first Memento variant simply encrypts files in the compromised machine.
In addition, several interesting connections were found between the Phosphorus group and the Memento Ransomware that first emerged in late 2021.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a possible ransomware association for a reverse-shell incident; the article links infrastructure reputation to Memento but does not provide malware behavior details beyond that association.
A Python 3.9/PyInstaller-compiled ransomware that initially attempted direct file encryption, then retooled to evade protection by archiving victim files into password-protected WinRAR archives with a .vaultz extension, encrypting the archive passwords, deleting originals, reporting telemetry to C2, and extorting victims with data-leak threats.
A Python 3.9/PyInstaller-compiled ransomware that evolved after its initial encryption attempt was blocked. Later variants archived victim files into password-protected WinRAR archives with a .vaultz extension, encrypted the per-file passwords, deleted originals, reported telemetry to a C2 server, and dropped a ransom note threatening data exposure.
Ransomware actor that, after failing to encrypt files, copied them into password-protected archives instead.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.