Actors Insights|Latest update09/07/2026

Memento Team

Named by self givenSuspected state sponsor: Islamic Republic of Iran

Memento Team is an Iranian-linked hacktivist group documented in 2021, known for deploying Python-based ransomware against organizations in Iran's regional adversary countries. The group targeted industrial and corporate organizations, encrypting files and demanding ransom payments. Researchers noted the malware lacked sophisticated capabilities compared to professional ransomware groups, suggesting Memento Team operated as a disruption-oriented persona rather than a financially motivated criminal actor. Activity was concentrated between May and November 2021, consistent with the short-lived persona pattern common across Iranian hacktivist operations.

First Seen:May 2021
Last Seen:Nov 2021
Indexed Reports:1
Public IOCs:54
Cluster: Loose Persona
also known as:
Memento Team (self given)

Targeted Regions

South Korea
KR
South Korea
South Korea
May 2021 ~ Nov 2021
May 2021 ~ Nov 2021
May 2021 ~ Nov 2021
Jan 2021Oct 2026

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.