Meow
Meow is a ransomware/extortion threat associated with Conti-derived code.
Profile source: Mallory opens in a new tabMeow
Family profile
Meow is a ransomware/extortion threat associated with Conti-derived code. Reporting in the provided content describes Meow ransomware as a variant of Conti that appends the ".MEOW" extension to encrypted files and uses the ChaCha20 encryption algorithm, while excluding .exe and text files. Infection and access vectors mentioned for Meow include unprotected RDP, email spam, and malicious downloads. Separate reporting in the content states that Meow later operated as a data-extortion-focused threat actor, also referred to as MeowLeaks or MeowCorp, first emerging in late 2022 and believed to be a Conti spinoff due to code similarities. That reporting says the group transitioned to a pure extortion model in which it steals sensitive data and publishes it on its leak site without deploying file-encrypting malware. The content also places Meow among active ransomware/extortion groups targeting U.S. organizations, including small and mid-sized U.S. organizations, and notes it was among the more active groups in U.S. ransomware victim reporting in 2024. A mutex name reused by DragonForce was noted as having previously been used by Meow and LockBit Green, further supporting linkage to Conti-based ransomware code. Aliases explicitly mentioned in the content are MeowLeaks and MeowCorp.