Memento Team's Innovative Ransomware Strategy: Bypassing Encryption Detection
- Actor Motivations: Exfiltration,Extortion,Financial Gain
- Attack Vectors: Compromised Credentials,Security Misconfiguration,Vulnerability Exploitation,Cryptojacking,Downloader,Dropper,Keylogger,Ransomware
- Attack Complexity: Medium
- Threat Risk: High Impact/High Probability
Threat Overview
Sophos discovered a novel ransomware approach by "Memento Team," which bypasses encryption detection by copying files into password-protected archives. Initially attempting direct encryption thwarted by endpoint protection, the actors retooled their method. They demanded $1 million for file restoration, threatening data exposure. The attack exploited a VMware vCenter Server vulnerability, with the attackers gaining initial access through a misconfigured firewall. Their activities included lateral movement using stolen credentials and deployment of a Python-based keylogger. The attack leveraged various tools like WinRAR, Mimikatz, and PowerShell, culminating in file archiving for ransom. The targeted sectors or countries were not specified in the report.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Region | South Korea | Verified |
Exploited Vulnerabilities
Extracted IOCs
- checkvisa[.]xyz
- novelengine[.]com
- transfer[.]sh
- xmrig[.]zip
- google.onedriver-srv[.]ml
- 07e1e386d8ffcc5b5ef1e55d6fb31a210522e2d9f1955dc24ba5c43523813612
- 09a0caadc4df3d4278368f94f52007894c2b51d3785d985cb8e42646e8a33b68
- 0bd68bd1e4567f15bc81c31d37971a71fc870781acb4cab0f51c675dcd779b5b
- 14f0c4ce32821a7d25ea5e016ea26067d6615e3336c3baa854ea37a290a462a8
- 1767cb41af0bbedf8554c5ddf7968cc1e039a06b7e4b7f9cd42ed4dd301bf02f
- 1a186d51bb4e4fd18acad387b2872d164e3a772e935b26c9fc673fdf53ccb533
- 3037956db905355f66cbd02ad9778f86551b0c34f386ee0adb7c2feb941a0e30
- 31eb1de7e840a342fd468e558e5ab627bcb4c542a8fe01aec4d5ba01d539a0fc
- 3bed84f229f5e8ca22c3768a7430ceb5e6e9ecb611df55691f07039e618f265b
- 48c6d499618d81280f7aa3acf6aecc2f37983f527f4a729b133ae6fca20ec8c7
- 654ad61bc4de2b9ad07add2dc7a6de22d24436f699bdb7923c7f510ee67b7e0a
- 6a4729fc8fc796318b44841e322c1f3bee37b2737e359e5e5b777d8855b370a6
- 7793b3b3545da61a7a073e64ac22c60fa38df8fbf0bbc95721a814992857c67a
- 8327eb8465d62959a40ea487c0fd0da178a8857e4b49a1594c5a2df3631ca179
- 91854f69ae78f5b5627c9e8800a1e5ef6f56b47a0193f03e260e362905770052
- 952476a3ead7a97ff9c4906a2801ad993e4850a3e10c4350bbd44ab2eeabbb02
- c3405d9c9d593d75d773c0615254e69d0362954384058ee970a3ec0944519c37
- c3757e7f49bd40012ef9cd320568c401bad1ba1843a4055b11bebc2f10bd83ca
- ca57391cdbac224f159e858425d231d068aa76316e0345cb8d58c716b9eff587
- cd7c9f1bd77e304a913758e95597d96399f823d887d7787fd8e9d8ec7a921d38
- ceec3cbb3a97c6be2c0446fcd74134ab8feec66f985bc50f17fb41350494c6ef
- d415ac7805edf8d634fbe6ac913e1e53a0d2ea0fce5146e0054056458a2a8f96
- e54d9a45850786f52b8169eceb1be0a4e21d5d000b933dda470b00d17c8fb169
- e9a096c886ce42c2dec0fae1492c2943a2e321fcff2a5697d1689ff146f4b4b6
- 123[.]45.67.89
- 169[.]51.60.221
- 183[.]110.224.164
- 190[.]144.115.54
- 195[.]201.124.214
- 27[.]102.127.120
- 27[.]102.66.114
- 45[.]77.76.158
- 78[.]138.105.150
- 169[.]51.60.221:1331/en-us/docs[.]html?type=&v=1
- 27[.]102.127.120/r[.]exe
- hxxp://190[.]144.115.54:443/mine[.]bat
- hxxp://27[.]102.127.120/r[.]exe
- hxxp://27[.]102.127.120/x1[.]rar
- hxxp://27[.]102.127.120/x2[.]rar
- hxxp://45[.]77.76.158:25643/w
- hxxp://78[.]138.105.150:11180/sv[.]php
- hxxp://lurchmath[.]org/wordpress-temp/wp-content/plugins/xmrig.zip
- hxxps://google.onedriver-srv[.]ml/gadfts55sghssss
- hxxps://raw.githubusercontent[.]com/c3pool/xmrig_setup/master/xmrig.zip
- transfer[.]sh/cnpw0x/connector3.exe
Tip: 50 related IOCs (9 IP, 5 domain, 12 URL, 0 email, 24 file hash) to this threat have been found.
Overlaps
Source: Cybersecurity and Infrastructure Security Agency - November 2022
Detection (one case): transfer[.]sh
Source: SentinelLabs - February 2022
Detection (one case): google.onedriver-srv[.]ml
Source: Cybereason - February 2022
Detection (one case): google.onedriver-srv[.]ml
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Memento Team Ransomware Incident
An organization suffered a cyberattack where intruders gained access to their network and locked their computer files. Instead of using traditional malware to scramble the data, the attackers placed the files into password-protected folders and deleted the originals. The attackers then demanded a $1 million ransom to provide the passwords and restore access to the data.
The attack was carried out by a relatively new cybercriminal group calling themselves the "Memento Team." While they are a newer group, they borrowed communication styles from older, well-known cybercriminal organizations and showed adaptability when their initial attacks failed.
The primary goal of the attack was financial extortion. The attackers aimed to disrupt the organization's operations by locking away critical files and threatening to publish stolen data online if their $1 million demand was not met.
The attackers had access to the network for several months, allowing them to map out the systems extensively. They managed to compromise administrative accounts, move across multiple machines, and deploy tracking tools directly onto the computer of the primary system administrator.
The report does not specify the exact industry of the victim, but it highlights that the primary system administrator was specifically targeted with a keystroke-logging tool to steal their passwords. The attackers broadly targeted the organization's files and administrative controls to maximize their leverage.
The attackers initially broke in through an outdated, internet-connected server that lacked proper security protections. Once inside, they quietly explored the network, stole administrative passwords, and eventually used a common file-compression tool to lock up the organization's data.
The organization was attractive because it had a critical server exposed to the internet with a known security flaw and outdated antivirus software. This easy point of entry allowed the attackers—and even other unrelated intruders—to quietly slip in and set up their operations without immediate detection.
Organizations should ensure that all their software is updated and that internal servers are not directly exposed to the public internet. Furthermore, deploying modern, active security monitoring tools on all computers and servers is crucial for catching intruders before they can lock down the network.
The specific method used by the Memento Team is highly tailored, as they manually adjusted their tactics when their first attempt was blocked by the victim's security software. However, the initial method of breaking in—finding an unpatched, exposed server—is a very widespread and common issue that affects many organizations globally.