morpheus logo

morpheus

11 incidentes 5 paises 5 sectores ransomware Ultimo: 2026-06-25
Ver en IntelTracker → APTTrail →
Morpheus is a ransomware and data extortion group that first emerged in late 2024, with its activity traceable back to at least September 2024, and its data leak site launching in December 2024. Operating as a semi-private Ransomware-as-a-Service (RaaS) model, Morpheus focuses on double-extortion by encrypting files and exfiltrating sensitive data for leverage. Its primary motivation is financial gain through a "big game hunting" strategy, targeting high-value organizations to maximize profit. What sets Morpheus apart is its unique extortion tactic of preferring private sales of stolen data over public leaks to control risk and extract larger sums, and its ransomware payloads do not alter file extensions, making detection potentially more challenging. Morpheus ransomware payloads are notably similar to those used by the HellCat operation, suggesting shared codebases or affiliates within the evolving ransomware ecosystem.

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
10
TTPs unicas
1
Info robada historica
N/D
Rescates reclamados
$432.8M
Pagos detectados
N/D

TTPs observadas

T1566 Phishing

Paises afectados

India (4) Denmark (1) United States (3) Tanzania (1) South Korea (1)

Paises objetivo (SOCRadar)

AustraliaBelgiumBrazilCanadaSwitzerlandChinaCosta RicaGermanyDenmarkSpain

Sectores atacados

Financial Services (2) Technology (2) Business Services (2) Agriculture and Food Production (1) Manufacturing (2)

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersReal EstateEnterprises & HoldingAccommodationManufacturingConstructionElectrical Equipment, Appliance, and Component Manufacturing

URLs nuevas detectadas en IntelTracker

duckduckgo.com duckduckgo.com ransomware.anggipradana.com

Victimas (10)

Delegal Poindexter & Underkofler, P.A.25 Jun 2026
Ransomware United States Business Services
Resumen La empresa Delegal Poindexter & Underkofler, P.A., un proveedor de servicios legales especializado en empleo, ha sido afectada por un ataque d…
HDFC FUND10 Jun 2026
Ransomware India Financial Services
Resumen HDFC FUND es una empresa de inversión líder en India con un volumen de negocio de $427.8 millones. La alerta de ransomware identifica a Morphe…
Ransomware Victim: HDFC FUND (morpheus)10 Jun 2026
Ransomware India
HDFC FUND Victima de ransomware reportada en el dashboard de morpheus. CampoValor Grupomorpheus PaisIN SectorFinancial Services Fecha2026-06-10T08:22:…
3I INFOTECH8 Jun 2026
Ransomware India Technology
Resumen Se ha emitido una alerta de ransomware relacionada con la empresa 3i Infotech, identificada como parte del grupo Morpheus. La compañía, regist…
Ransomware Victim: 3I INFOTECH (morpheus)8 Jun 2026
Ransomware India Technology
3I INFOTECH Victima de ransomware reportada en el dashboard de morpheus. CampoValor Grupomorpheus PaisIN SectorTechnology Fecha2026-06-08T12:25:05.060…
BAYTECH A/S14 May 2026
Ransomware Denmark Business Services
Resumen Se ha reportado una alerta de ransomware relacionada con la empresa Baytech A/S, un proveedor de sistemas de grúas y soluciones logísticas en …
GGI21 Apr 2026
Ransomware United States Financial Services
Resumen Se ha reportado una alerta de ransomware relacionada con el grupo Morpheus que afectó a la empresa GGI. La organización, especializada en segu…
SBCTANZANIA30 Mar 2026
Ransomware Tanzania Agriculture and Food Production
Resumen SBC Tanzania Limited, una empresa de fabricación y distribución de bebidas en Tanzania, ha sido identificada como objetivo de un ataque ransom…
SURTECHINC27 Feb 2026
Ransomware South Korea Manufacturing
Resumen SURTECHINC, una empresa líder en la industria del revestimiento con un ingreso anual de $5 millones, ha sido alertada sobre un ataque de ranso…
SUNSETWORLDRESORTS29 Jan 2026
Ransomware Mexico Hospitality and Tourism
Resumen Sunset World Resorts, un grupo hotelero mexicano con sede en Cancún, ha sido objeto de una alerta de ransomware el 2026-01-29. La empresa, con…