Threats Feed|Memento Team|Last Updated 22/05/2026|AuthorCertfa Radar|Publish Date18/11/2021

Memento Team's Innovative Ransomware Strategy: Bypassing Encryption Detection

  • Actor Motivations: Exfiltration,Extortion,Financial Gain
  • Attack Vectors: Compromised Credentials,Security Misconfiguration,Vulnerability Exploitation,Cryptojacking,Downloader,Dropper,Keylogger,Ransomware
  • Attack Complexity: Medium
  • Threat Risk: High Impact/High Probability

Threat Overview

Sophos discovered a novel ransomware approach by "Memento Team," which bypasses encryption detection by copying files into password-protected archives. Initially attempting direct encryption thwarted by endpoint protection, the actors retooled their method. They demanded $1 million for file restoration, threatening data exposure. The attack exploited a VMware vCenter Server vulnerability, with the attackers gaining initial access through a misconfigured firewall. Their activities included lateral movement using stolen credentials and deployment of a Python-based keylogger. The attack leveraged various tools like WinRAR, Mimikatz, and PowerShell, culminating in file archiving for ransom. The targeted sectors or countries were not specified in the report.

Detected Targets

TypeDescriptionConfidence
RegionSouth Korea
Verified

Exploited Vulnerabilities

Extracted IOCs

  • checkvisa[.]xyz
  • novelengine[.]com
  • transfer[.]sh
  • xmrig[.]zip
  • google.onedriver-srv[.]ml
  • 07e1e386d8ffcc5b5ef1e55d6fb31a210522e2d9f1955dc24ba5c43523813612
  • 09a0caadc4df3d4278368f94f52007894c2b51d3785d985cb8e42646e8a33b68
  • 0bd68bd1e4567f15bc81c31d37971a71fc870781acb4cab0f51c675dcd779b5b
  • 14f0c4ce32821a7d25ea5e016ea26067d6615e3336c3baa854ea37a290a462a8
  • 1767cb41af0bbedf8554c5ddf7968cc1e039a06b7e4b7f9cd42ed4dd301bf02f
  • 1a186d51bb4e4fd18acad387b2872d164e3a772e935b26c9fc673fdf53ccb533
  • 3037956db905355f66cbd02ad9778f86551b0c34f386ee0adb7c2feb941a0e30
  • 31eb1de7e840a342fd468e558e5ab627bcb4c542a8fe01aec4d5ba01d539a0fc
  • 3bed84f229f5e8ca22c3768a7430ceb5e6e9ecb611df55691f07039e618f265b
  • 48c6d499618d81280f7aa3acf6aecc2f37983f527f4a729b133ae6fca20ec8c7
  • 654ad61bc4de2b9ad07add2dc7a6de22d24436f699bdb7923c7f510ee67b7e0a
  • 6a4729fc8fc796318b44841e322c1f3bee37b2737e359e5e5b777d8855b370a6
  • 7793b3b3545da61a7a073e64ac22c60fa38df8fbf0bbc95721a814992857c67a
  • 8327eb8465d62959a40ea487c0fd0da178a8857e4b49a1594c5a2df3631ca179
  • 91854f69ae78f5b5627c9e8800a1e5ef6f56b47a0193f03e260e362905770052
  • 952476a3ead7a97ff9c4906a2801ad993e4850a3e10c4350bbd44ab2eeabbb02
  • c3405d9c9d593d75d773c0615254e69d0362954384058ee970a3ec0944519c37
  • c3757e7f49bd40012ef9cd320568c401bad1ba1843a4055b11bebc2f10bd83ca
  • ca57391cdbac224f159e858425d231d068aa76316e0345cb8d58c716b9eff587
  • cd7c9f1bd77e304a913758e95597d96399f823d887d7787fd8e9d8ec7a921d38
  • ceec3cbb3a97c6be2c0446fcd74134ab8feec66f985bc50f17fb41350494c6ef
  • d415ac7805edf8d634fbe6ac913e1e53a0d2ea0fce5146e0054056458a2a8f96
  • e54d9a45850786f52b8169eceb1be0a4e21d5d000b933dda470b00d17c8fb169
  • e9a096c886ce42c2dec0fae1492c2943a2e321fcff2a5697d1689ff146f4b4b6
  • 123[.]45.67.89
  • 169[.]51.60.221
  • 183[.]110.224.164
  • 190[.]144.115.54
  • 195[.]201.124.214
  • 27[.]102.127.120
  • 27[.]102.66.114
  • 45[.]77.76.158
  • 78[.]138.105.150
  • 169[.]51.60.221:1331/en-us/docs[.]html?type=&v=1
  • 27[.]102.127.120/r[.]exe
  • hxxp://190[.]144.115.54:443/mine[.]bat
  • hxxp://27[.]102.127.120/r[.]exe
  • hxxp://27[.]102.127.120/x1[.]rar
  • hxxp://27[.]102.127.120/x2[.]rar
  • hxxp://45[.]77.76.158:25643/w
  • hxxp://78[.]138.105.150:11180/sv[.]php
  • hxxp://lurchmath[.]org/wordpress-temp/wp-content/plugins/xmrig.zip
  • hxxps://google.onedriver-srv[.]ml/gadfts55sghssss
  • hxxps://raw.githubusercontent[.]com/c3pool/xmrig_setup/master/xmrig.zip
  • transfer[.]sh/cnpw0x/connector3.exe
download

Tip: 50 related IOCs (9 IP, 5 domain, 12 URL, 0 email, 24 file hash) to this threat have been found.

Overlaps

UnclassifiedIranian APTs Exploit Log4Shell to Compromise FCEB Network

Source: Cybersecurity and Infrastructure Security Agency - November 2022

Detection (one case): transfer[.]sh

TunnelVisionTunnelVision Exploits 1-Day Vulnerabilities to Unleash Ransomware

Source: SentinelLabs - February 2022

Detection (one case): google.onedriver-srv[.]ml

PhosphorusPowerLess Backdoor: Analyzing the Phosphorus Group's Cyber Espionage Tool

Source: Cybereason - February 2022

Detection (one case): google.onedriver-srv[.]ml

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Memento Team Ransomware Incident

An organization suffered a cyberattack where intruders gained access to their network and locked their computer files. Instead of using traditional malware to scramble the data, the attackers placed the files into password-protected folders and deleted the originals. The attackers then demanded a $1 million ransom to provide the passwords and restore access to the data.

The attack was carried out by a relatively new cybercriminal group calling themselves the "Memento Team." While they are a newer group, they borrowed communication styles from older, well-known cybercriminal organizations and showed adaptability when their initial attacks failed.

The primary goal of the attack was financial extortion. The attackers aimed to disrupt the organization's operations by locking away critical files and threatening to publish stolen data online if their $1 million demand was not met.

The attackers had access to the network for several months, allowing them to map out the systems extensively. They managed to compromise administrative accounts, move across multiple machines, and deploy tracking tools directly onto the computer of the primary system administrator.

The report does not specify the exact industry of the victim, but it highlights that the primary system administrator was specifically targeted with a keystroke-logging tool to steal their passwords. The attackers broadly targeted the organization's files and administrative controls to maximize their leverage.

The attackers initially broke in through an outdated, internet-connected server that lacked proper security protections. Once inside, they quietly explored the network, stole administrative passwords, and eventually used a common file-compression tool to lock up the organization's data.

The organization was attractive because it had a critical server exposed to the internet with a known security flaw and outdated antivirus software. This easy point of entry allowed the attackers—and even other unrelated intruders—to quietly slip in and set up their operations without immediate detection.

Organizations should ensure that all their software is updated and that internal servers are not directly exposed to the public internet. Furthermore, deploying modern, active security monitoring tools on all computers and servers is crucial for catching intruders before they can lock down the network.

The specific method used by the Memento Team is highly tailored, as they manually adjusted their tactics when their first attempt was blocked by the victim's security software. However, the initial method of breaking in—finding an unpatched, exposed server—is a very widespread and common issue that affects many organizations globally.

About Affiliation
Memento Team
Memento Team is an Iranian-linked hacktivist group documented in 2021, known for deploying Python-based ransomware against organizations in Iran's regional adversary countries. The group targeted industrial and corporate organizations, encrypting files and demanding ransom payments. Researchers noted the malware lacked sophisticated capabilities compared to professional ransomware groups, suggesting Memento Team operated as a disruption-oriented persona rather than a financially motivated criminal actor. Activity was concentrated between May and November 2021, consistent with the short-lived persona pattern common across Iranian hacktivist operations.
View Memento Team's Insights