Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors morpheus

Description

Morpheus emerged in late 2024 as a semi-private RaaS operation whose affiliates share identical payloads with the HellCat ransomware group, targeting pharmaceutical, manufacturing, legal, and Italian ESXi environments with ransom demands reaching up to 32 BTC (~$3M USD). Known victims: 16 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Morpheus, identified as a semi-private ransomware-as-a-service (RaaS) operation, has emerged as a significant threat actor targeting pharmaceutical, manufacturing, legal, and Italian ESXi environments. Primarily motivated by financial gain, Morpheus affiliates share payloads with the HellCat ransomware group, demanding ransoms up to 32 BTC (~$3M USD). With known victims across diverse sectors, Morpheus poses a growing risk, particularly to organizations operating in high-value industries.

Goals & Targeting

Morpheus primarily aims for financial gain via ransomware deployment. Their targeting strategy focuses on sectors with significant financial resources or sensitive data, such as pharmaceuticals (due to research value) and legal industries (with Intellectual Property). Italian ESXi environments suggest a regional interest. Morpheus' choice of victims reflects their objective to maximize ransom payments, preferring organizations where downtime incurs high costs.

Enhanced Description

Morpheus is a moderately sophisticated criminal threat actor operating as a semi-private RaaS entity. Emerging in late 2024, Morpheus has demonstrated the ability to compromise diverse targets, leveraging shared payloads with the HellCat group. Their victims include prominent entities such as GGI Group, SBCTANZANIA, BAYTECH A/S, and others across pharmaceuticals, legal, manufacturing, and IT sectors. The actor's operations span multiple geographies, though exact targeting by country remains unclear. Morpheus' financial motivation is evident through their hefty ransom demands, reaching up to 32 BTC ($3M USD), indicating a focus on high-value targets to maximize illicit gains.

Key Capabilities

  • Affiliation with the HellCat ransomware group
  • Deployment capability via a semi-private RaaS model
  • Expertise in compromising diverse industrial and organizational targets
  • Experience in multi-sector campaigns, indicating operational versatility

MITRE ATT&CK Tactics

Credential Access
Data Exfiltration
Defense Evasion
Impact Tools

ATT&CK Techniques

T1053
T1078
T1249
T1059

Software / Tooling

HellCat Ransomware
Mimikatz for credential extraction
Custom tools for initial access and lateral movement

Campaigns & Victims

Morpheus has conducted campaigns targeting GGI Group, Hansa Research, and others. Their approach includes prolonged dwell time to ensure effective data exfiltration before ransomware deployment. The actor's campaigns demonstrate a focus on high-value victims across various industries, indicating an operational model designed for scalability and profitability.

IOC Patterns

  • Spear-phishing emails with macro-laced Office documents
  • Use of shared payloads similar to HellCat ransomware
  • Lateral movement using SMB or RDP protocols
  • Data encryption targeting sensitive directories

Recommended Actions

  • Implement multi-layered email filtering and threat detection for phishing attempts.
  • Monitor file-sharing and network drives for unauthorized access and anomalies.
  • Enhance endpoint detection to identify known HellCat and Morpheus ransomware signatures.
  • Enforce strict backup protocols to mitigate potential ransomware impacts.
  • Conduct regular training sessions to recognize spear-phishing campaigns.

Suggested Tags

Ransomware
Organized Crime
Financial Gain
Manufacturing Sector Targeting

Confidence Assessment

Confidence in Morpheus' details is medium. Data on TTPs, geographic targeting, and specific toolkits remains limited. The actor's relative newness (first seen in 2025) compounds understanding, but HellCat's attributes provide partial context. Key unknowns include the extent of their global operations and the full scope of their toolset.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

9

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
Organized Crime
Financial Gain
Manufacturing Sector Targeting

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Jan 7, 2025
Last Seen
Jul 30, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.