Morpheus is a ransomware and data-extortion operation active by at least 2025 and continuing through 2026. It has been observed claiming victims across multiple countries, including India, the United States, Singapore, and South Korea, with reported victims spanning manufacturing, business services, information technology, and financial services. Publicly reported incidents include attacks against HDFC Asset Management Company, 3i Infotech, Hansa Research Group, Kyowa Singapore, Yue Ki Industrial, and Delegal Poindexter & Underkofler. Morpheus operates a leak site and has used stolen-data publication threats as part of its extortion model. In the HDFC AMC incident, the group claimed large-scale data theft and threatened disclosure unless the victim engaged within a short deadline, later listing the victim on its leak site. This demonstrates a data-theft-driven ransomware workflow combining intrusion, exfiltration, and public shaming/extortion. Reporting has linked Morpheus closely to the HellCat ransomware operation. Security analysis found the ransomware binaries used by Morpheus and HellCat to be effectively identical aside from branding-related differences, and the two operations have been described as distinct brands deploying the same payloads. This suggests either shared operators, shared developers, or a white-label/rebranding relationship, although public attribution does not conclusively establish the exact organizational structure. Morpheus is associated with ransomware intrusions that include post-compromise data theft and likely follow-on internal movement and defense evasion consistent with modern extortion operations. In the HDFC AMC case, compromised infrastructure reportedly included VPN, SFTP, and security-management systems, indicating meaningful post-exploitation capability and probable staged exfiltration. Separate reporting has also associated the Morpheus name with Android spyware activity abusing Accessibility features to enable developer functionality and wireless debugging, but the relationship between that mobile activity and the ransomware operation is not sufficiently established to treat it as core actor tradecraft. No high-confidence public attribution to a specific state or country of origin is established. Morpheus is best characterized as a financially motivated cybercriminal ransomware/extortion actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An existing ransomware/data theft group noted as continuing operations.
Conducting a ransomware attack resulting in a data breach against Yue Ki Industrial, a manufacturing company.
Conducting a ransomware attack against Kyowa Singapore Pte Ltd.
Named as a data extortion actor claiming theft of a large volume of data from a financial-sector organization.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.