Memento is a ransomware operation first observed in 2021 and associated with a group identifying itself as Memento Team. It is notable for an unusual file-locking approach: after an initial direct-encryption attempt was disrupted, the operators adapted the malware to copy victim files into password-protected archives using a renamed WinRAR utility, encrypt the archive passwords, and delete the original files. Earlier variants also included conventional cryptographic routines using AES and RSA, but later iterations emphasized archive-based denial of access rather than direct content encryption. The ransomware payload has been described as a Python 3.9 program compiled with PyInstaller, and operators manually deployed ransom notes while threatening to leak stolen data unless payment was made, indicating a double-extortion model.
Intrusions attributed to Memento involved exploitation of VMware vCenter Server, specifically CVE-2021-21972, for initial access. After compromise, the actors conducted extended hands-on-keyboard operations, including credential theft, lateral movement over RDP, reconnaissance, data staging, and exfiltration prior to ransomware deployment. Reported tooling used during these operations included Impacket components, Mimikatz, Plink, WinRAR, Process Hacker, BCWipe, and a Python-based keylogger. The group also attempted to weaken defenses and remove evidence, including disabling security controls, clearing logs, altering timestamps, and using scheduled tasks and service-based mechanisms for persistence.
Memento activity has been linked by multiple researchers to overlaps in tactics, infrastructure, and tradecraft with the Iranian threat actor APT35, also known as Charming Kitten or Phosphorus, though that relationship has been presented as an assessed connection rather than definitive public attribution. Victimology in the documented case centered on enterprise Windows environments reachable through exposed virtualization management infrastructure. Memento is best characterized as a manually operated ransomware threat that combines credential theft, lateral movement, exfiltration, and defense evasion with an uncommon archive-and-password encryption scheme to deny access to victim data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Cybereason also found evidence that links the APT group to the Memento Ransomware operations that first appeared in the threat landscape in 2021.
"The activity of Phosphorus with regard to ProxyShell took place in about the same time frame as Memento," the Cybereason Nocturnus Team said.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cybereason also found evidence that links the APT group to the Memento Ransomware operations that first appeared in the threat landscape in 2021.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a possible ransomware association for a reverse-shell incident; the article links infrastructure reputation to Memento but does not provide malware behavior details beyond that association.
A Python 3.9/PyInstaller-compiled ransomware that initially attempted direct file encryption, then retooled to evade protection by archiving victim files into password-protected WinRAR archives with a .vaultz extension, encrypting the archive passwords, deleting originals, reporting telemetry to C2, and extorting victims with data-leak threats.
A Python 3.9/PyInstaller-compiled ransomware that evolved after its initial encryption attempt was blocked. Later variants archived victim files into password-protected WinRAR archives with a .vaultz extension, encrypted the per-file passwords, deleted originals, reported telemetry to a C2 server, and dropped a ransom note threatening data exposure.
Ransomware actor that, after failing to encrypt files, copied them into password-protected archives instead.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.