Memento, also calling itself Memento Team, is a ransomware and data-extortion operation active since 2021 that has been linked by multiple researchers to Iranian threat activity and possible overlap with APT35/Phosphorus/Charming Kitten. The group is notable for an unusual ransomware approach: after an initial direct-encryption attempt was disrupted, it shifted to copying victim files into password-protected archives using a renamed legitimate archiving utility, encrypting the archive passwords, deleting the original files, and then demanding payment for recovery while threatening exposure of stolen data. This behavior constitutes double extortion and reflects adaptation to endpoint defenses. Memento has been observed gaining initial access through exploitation of internet-exposed VMware vCenter Server vulnerabilities, including CVE-2021-21972. In at least one documented intrusion, the actors maintained access for months before deploying ransomware. Post-compromise activity included credential theft with publicly available offensive tooling, lateral movement via RDP, SSH tunneling, reconnaissance with network and disk-enumeration utilities, deployment of a Python-based keylogger, data staging and exfiltration, persistence through scheduled tasks and driver-backed tooling, and defense evasion through log clearing and timestamp manipulation. The ransomware payloads were Python programs compiled with PyInstaller and were manually propagated using stolen credentials. Researchers have reported infrastructure, tooling, naming, and TTP overlaps between Memento and the Iranian state-aligned cluster tracked as APT35, Phosphorus, or Charming Kitten. Reported overlaps include shared operational patterns around exploitation of enterprise-facing services, use of PowerShell and proxy tooling, and common infrastructure associations. While the exact organizational relationship has not been publicly established with complete certainty, the available reporting supports a high-confidence Iranian nexus for Memento. The group’s operations indicate financially motivated extortion activity, potentially intersecting with broader Iranian intrusion ecosystems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Potentially related to a PowerShell reverse shell incident following VMware Horizon Log4Shell exploitation, but attribution is tentative.
Conducting hands-on-keyboard ransomware intrusions with long dwell time, exploiting exposed VMware vCenter Server, moving laterally via RDP, stealing credentials, exfiltrating data, and deploying a Python/PyInstaller ransomware that archives files into password-protected WinRAR archives instead of conventional file encryption.
Conducting ransomware and double-extortion attacks using a custom Python/PyInstaller payload that archives victim files into password-protected WinRAR archives, exfiltrates data, moves laterally via RDP, deploys keylogging, and evades detection by changing tactics after endpoint protection blocked direct encryption.
Ransomware operation potentially connected to Phosphorus through shared infrastructure, IOC overlaps, naming conventions, and similar TTPs.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.