Meow — Ransomware Profile
Meow is a ransomware and data extortion operation classified by Bitdefender as a variant within the Conti malware family, which emerged following the 2022 leak of Conti source code alongside BlueSky, ScareCrow and Putin Team. A related brand, Meow Leaks, surfaced in 2023 and leans toward exfiltration and extortion rather than encryption, though researchers still identified a ransomware encryptor during incident analysis. There is ongoing debate over whether Meow and Meow Leaks are one group operating under two aliases or two distinct entities with different operational models. Observed victims span government, healthcare, education, technology and finance in the United States, United Kingdom, Germany and Japan.
Tools & malware
- MegaSync Exfiltration Tool
- NetScan Network Reconnaissance
- PowerTool32.exe Defense Evasion
- PowerTool64.exe Defense Evasion
- truenight.sys Vulnerable Driver
Recent claimed victims
Vendor research
Read the full analysis on IntelFusions