Meow Ransomware, also known as MeowLeaks and MeowCorp, is a financially motivated ransomware and data-extortion operation that emerged in late 2022. It has been associated with dedicated leak-site activity, including postings involving healthcare entities, and has been particularly active against small and mid-sized organizations in the United States. Meow has also been assessed among the more active ransomware groups targeting U.S. organizations during 2024. A ransomware variant attributed to Meow has been characterized as Conti-derived. It encrypts a broad range of files using ChaCha20 and appends a distinctive extension, while excluding executable and text files. Reported access vectors include exposed or inadequately secured Remote Desktop Protocol services, spam-based delivery, and malicious downloads. The operation uses public leak-site postings to pressure victims and has been described as data-extortion focused, including claims involving data taken from compromised web servers or databases.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with healthcare-sector dedicated leak-site postings.
Referenced as a ransomware group whose victim listings were allegedly copied by an impersonator; no direct activity described in this content.
Referenced as a group whose victim listings were allegedly copied by a Babuk impersonator to fabricate victims.
A data extortion group (no encryption) believed to be a Conti spinoff, targeting healthcare, financial services, professional services, and education, especially small and mid-sized US organizations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.