Morpheus emerged in late 2024 as a semi-private RaaS operation whose affiliates share identical payloads with the HellCat ransomware group, targeting pharmaceutical, manufacturing, legal, and Italian ESXi environments with ransom demands reaching up to 32 BTC (~$3M USD). Known victims: 16 1 ransom note(s) on file
Objectives
Executive Summary
Morpheus, identified as a semi-private ransomware-as-a-service (RaaS) operation, has emerged as a significant threat actor targeting pharmaceutical, manufacturing, legal, and Italian ESXi environments. Primarily motivated by financial gain, Morpheus affiliates share payloads with the HellCat ransomware group, demanding ransoms up to 32 BTC (~$3M USD). With known victims across diverse sectors, Morpheus poses a growing risk, particularly to organizations operating in high-value industries.
Goals & Targeting
Morpheus primarily aims for financial gain via ransomware deployment. Their targeting strategy focuses on sectors with significant financial resources or sensitive data, such as pharmaceuticals (due to research value) and legal industries (with Intellectual Property). Italian ESXi environments suggest a regional interest. Morpheus' choice of victims reflects their objective to maximize ransom payments, preferring organizations where downtime incurs high costs.
Enhanced Description
Morpheus is a moderately sophisticated criminal threat actor operating as a semi-private RaaS entity. Emerging in late 2024, Morpheus has demonstrated the ability to compromise diverse targets, leveraging shared payloads with the HellCat group. Their victims include prominent entities such as GGI Group, SBCTANZANIA, BAYTECH A/S, and others across pharmaceuticals, legal, manufacturing, and IT sectors. The actor's operations span multiple geographies, though exact targeting by country remains unclear. Morpheus' financial motivation is evident through their hefty ransom demands, reaching up to 32 BTC ($3M USD), indicating a focus on high-value targets to maximize illicit gains.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Morpheus has conducted campaigns targeting GGI Group, Hansa Research, and others. Their approach includes prolonged dwell time to ensure effective data exfiltration before ransomware deployment. The actor's campaigns demonstrate a focus on high-value victims across various industries, indicating an operational model designed for scalability and profitability.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in Morpheus' details is medium. Data on TTPs, geographic targeting, and specific toolkits remains limited. The actor's relative newness (first seen in 2025) compounds understanding, but HellCat's attributes provide partial context. Key unknowns include the extent of their global operations and the full scope of their toolset.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
9
Campaigns
0
IOCs
0
Observed Data
0
Tactics