Sophos reported that the Memento Team gained initial access by exploiting an exposed VMware vCenter Server vulnerability, then remained in the victim environment for more than six months while stealing credentials, moving laterally over RDP, and exfiltrating data. During that dwell time, the same exposed server was also compromised by unrelated intruders who deployed XMR and XMRig cryptocurrency miners, underscoring the prolonged exposure of the environment.
After a failed attempt to encrypt files directly, Memento reworked its malware to evade encryption protections by placing victim files into password-protected WinRAR archives, encrypting the archive passwords, and deleting the originals before issuing a ransom demand of about $1 million in Bitcoin and threatening to leak stolen data. Sophos said the payloads were Python 3.9 programs packaged with PyInstaller, communicated with a command-and-control server at 78.138.105.150:11180, and used ransom-note styling similar to REvil while directing victims to Telegram; the victim restored most systems from backups, and investigators recovered some files because endpoint telemetry captured archive passwords during the attack.

TTPs, infrastructure, and targeting history in one profile.
10 events from the most recent confirmed update back to the earliest known activity.
Sophos MTR's Rapid Response Team encountered the new ransomware group calling itself Memento Team in late October. The case revealed a long-running intrusion involving lateral movement, credential theft, and data exfiltration before ransomware deployment.
In October, the Memento gang installed Process Hacker on their primary foothold server and configured its kernel driver as a persistence service. This marked a further step in maintaining access on the victim network.
On September 28, the Memento attackers dropped another Plink binary via transfer.sh, disguised it as MicrosoftOutlookUpdater.exe, and used it to create a reverse shell to google.onedriver-srv.ml under the account name dontstarve. They also created a scheduled task named GoogleChangeManagementSchedule to exchange reconnaissance data with that host.
On September 8, an unrelated actor installed an XMRig miner and NSSM using PowerShell and files fetched from 190.144.115.54, lurchmath.org, and later GitHub. Sophos noted multiple actors had exploited the same exposed vCenter server.
On May 18, a different intruder exploited the same vCenter vulnerability to install an XMR cryptocurrency miner via PowerShell from 45.77.76.158:25643. The miner registered the WinRing0x64.sys driver as a service to use the server's graphics card for mining.
On May 10, the intruders used PowerShell to try to disable Microsoft Defender real-time monitoring. This was part of their effort to weaken defenses during the intrusion.
On May 4, attackers dropped PyInstaller-compiled Impacket tools including wmiexec and secretsdump onto a Windows server. Sophos said the tools were likely used to obtain credentials for later operations.
Sophos reported the victim's exposed VMware vCenter Server was likely exploited for initial access by the Memento intrusion, with evidence suggesting access may have begun as early as mid-April. The server was internet-exposed and lacked adequate endpoint detection and response.
The attackers demanded 15.95 BTC, roughly $1 million, for file recovery and threatened to expose stolen data if the victim did not pay. The ransom note borrowed REvil-style formatting and directed the victim to contact the attackers via Telegram.
After an initial direct-encryption attempt was blocked by endpoint protection, the attackers modified their malware to copy files into password-protected WinRAR archives, encrypt the archive passwords, and delete the originals. This unusual approach was used to bypass encryption protections.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 19 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.