Morpheus is a ransomware and data-extortion threat actor that emerged by early 2025 and has been observed targeting organizations across multiple sectors and geographies, including financial services, technology, professional services, manufacturing, and business services in countries such as India, Singapore, South Korea, and the United States. Publicly reported victim claims and incident reporting indicate a conventional double-extortion model in which the group alleges data theft and pressures victims with the threat of publication on a leak site. Morpheus has been associated with leak-site postings and extortion claims against organizations including HDFC Asset Management Company, 3i Infotech, Hansa Research Group, Kyowa Singapore, and Delegal Poindexter & Underkofler. In the HDFC AMC intrusion, the actor claimed to have exfiltrated a very large volume of data and later listed the victim under an alternate name on its leak site, indicating an operational pattern centered on public shaming and coercive disclosure threats. A notable aspect of Morpheus is its reported overlap with HellCat. Security research has assessed that Morpheus and HellCat operated as distinct brands while deploying effectively identical ransomware binaries, differing primarily in branding-related elements. This suggests either shared operators, a white-label arrangement, or closely aligned affiliates, and makes attribution based solely on payload characteristics unreliable. Morpheus has been identified among newly emerging ransomware groups active in the 2025 threat landscape. Available reporting places it within the broader ransomware ecosystem rather than clearly tying it to a specific nation-state. Its observed tradecraft is consistent with modern financially motivated ransomware operations: intrusion into enterprise environments, likely lateral movement and defense evasion, data exfiltration, encryption or extortion staging, and publication threats via a dark web leak site. Public reporting on specific initial access methods remains limited, and high-confidence attribution to a sponsoring state or a larger established cluster is currently not available. Known aliasing is limited, with Morpheus itself being the primary name in circulation. HellCat should be considered a closely related parallel brand rather than a confirmed formal alias.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against Kyowa Singapore Pte Ltd.
Named as a data extortion actor claiming theft of a large volume of data from a financial-sector organization.
Conducting a ransomware attack resulting in a data breach against Hansa Research Group Pvt. Ltd.
Conducting a ransomware attack against Delegal Poindexter & Underkofler, P.A.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.