The Memento ransomware group reportedly breached a victim’s network in April 2021 by exploiting CVE-2021-21972, a critical remote code execution vulnerability in a VMware vCenter Server plugin. The attackers maintained access for more than five months, using credential-theft tools and remote-access techniques before exfiltrating data and deploying Python-based ransomware in late October. When anti-ransomware protection blocked their initial file-encryption attempt, they switched to placing the victim’s files into password-protected archives. VMware had released a patch in February 2021, and CISA urged administrators to apply it on February 24, before the reported intrusion.
Administrators should prioritize patching affected vCenter systems; VMware also documents a workaround for CVE-2021-21972 and CVE-2021-21973 under advisory VMSA-2021-0002. The workaround requires marking the vROPS Client plugin package com.vmware.vrops.install as incompatible in compatibility-matrix.xml; merely disabling the plugin in the user interface does not protect affected systems. VMware provides procedures for both appliance and Windows deployments, requiring a restart of the vSphere UI service and verification that the plugin appears incompatible and its check endpoint returns HTTP 404. In vCenter High Availability environments, administrators must apply the workaround to both active and passive nodes.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
The attackers deployed Python-based Memento ransomware in late October after exfiltrating data. Anti-ransomware protection blocked the initial variant's attempt to encrypt files on compromised machines.
In late October, the attackers collected files from compromised machines and used WinRAR to archive them for exfiltration. They completed the data theft before deploying the initial ransomware variant.
The attackers deployed wmiexec and secretsdump to a Windows server in the victim's network. These tools support remote command execution through Windows Management Instrumentation and extraction of credential material.
According to Sophos, the Memento attackers gained initial access to an unnamed victim's network by exploiting CVE-2021-21972. They remained in the network for more than five months before deploying ransomware.
CISA issued an alert urging administrators to promptly apply VMware's patch for the critical vCenter Server vulnerability.
VMware released a patch for CVE-2021-21972, a remote code execution vulnerability with a CVSS score of 9.8, and documented it in advisory VMSA-2021-0002.
VMware provided workaround instructions for CVE-2021-21972 and CVE-2021-21973 that require marking the vROPS Client plugin as incompatible and restarting the vsphere-ui service. The guidance warns that disabling the plugin through the UI does not protect affected systems and that both active and passive nodes require mitigation in high-availability deployments.
After the initial encryption attempt failed, the attackers changed tactics to place victim files into password-protected archives. The second Memento variant collected files and packaged them into these archives rather than encrypting the files directly.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.