Sophos reported that the Memento Team compromised a victim network through an exposed, unpatched VMware vCenter Server and remained inside the environment for more than six months. The attackers conducted hands-on-keyboard operations over RDP, used tools including Impacket, Mimikatz, Plink, Process Hacker, BCWipe, and a Python keylogger, and also exfiltrated data while threatening to leak it publicly as part of a $1 million extortion demand.
After an initial attempt to encrypt files was partly blocked by endpoint protection, the group changed tactics and used password-protected WinRAR archives to bypass encryption defenses: they copied victim files into encrypted archives, encrypted the archive passwords, and deleted the originals. Sophos said the same exposed vCenter server was also exploited by other intruders to deploy XMR and XMRig cryptocurrency miners during the intrusion window, while the victim ultimately restored most systems from backups and investigators recovered some files because security logs had captured the archive passwords.

TTPs, infrastructure, and targeting history in one profile.
10 events from the most recent confirmed update back to the earliest known activity.
The attackers demanded 15.95 BTC, about $1 million, to restore files and threatened to expose stolen data if the victim did not pay. The victim ultimately restored most data from backups, and Sophos recovered some files because Intercept X logs captured archive passwords during the attack.
After endpoint protection partially blocked an initial direct-encryption attempt, the attackers recompiled and redeployed their ransomware in a new form. The revised malware copied files into password-protected WinRAR archives, encrypted the archive passwords, and deleted the original files to evade detection.
Sophos MTR's Rapid Response Team encountered a new ransomware group identifying itself as Memento Team in late October. The group had compromised the victim through an exposed, unpatched VMware vCenter Server vulnerability and maintained access for more than six months.
On October 20, the attackers used WinRAR to compress files for exfiltration and staged the archives on a shared drive accessible over RDP. The intrusion also involved theft of data used to pressure the victim with exposure threats.
In October, the Memento actors deployed Process Hacker and configured its kernel driver as a persistence mechanism. This expanded their foothold during the later stage of the intrusion.
On September 28, the attackers deployed a Plink binary named MicrosoftOutlookUpdater.exe to create a reverse shell to google.onedriver-srv.ml under the dontstarve account. They also scheduled a task named GoogleChangeManagementSchedule to upload host IP data and exchange reconnaissance data with their remote server.
On September 8, a separate intruder deployed an XMRig miner on the compromised vCenter server. The actor later used NSSM to manage services associated with the miner.
On May 18, a different actor exploited the same exposed VMware vCenter vulnerability to install an XMR cryptocurrency miner from 45.77.76.158:25643. The miner registered the WinRing0x64.sys driver as a service to use the server's graphics hardware for mining.
On May 10, the intruders used PowerShell to attempt to disable Microsoft Defender real-time monitoring. This was part of their effort to weaken defenses after initial access.
The first clear intrusion activity occurred on May 4, when PyInstaller-compiled Impacket tools including wmiexec and secretsdump were dropped onto a Windows server. Sophos assessed the attackers likely used secretsdump to obtain credential hashes for later account compromise.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 20 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.