Morpheus is a name used for at least two distinct malware contexts in the provided content: an Android spyware family and a ransomware strain. The Android spyware, reported by Osservatorio Nessuno in 2026, is distributed via fake Android apps masquerading as updates or service-restoration applications, often delivered through SMS links to ISP-impersonation phishing sites. It uses a multi-stage infection chain with a first-stage dropper and a hidden second-stage payload disguised as legitimate Android system components. The spyware abuses Accessibility and overlay permissions, displays fake update and reboot screens, enables Developer Options and Wireless Debugging, pairs locally with adbd, and uses ADB access to silently grant itself sensitive permissions and increase control without requiring root. Reported capabilities include stealing extensive device data, reading screens, interacting with apps, recording audio and video, manipulating WhatsApp device linking via deceptive prompts, disabling security protections such as Google Play Protect and multiple antivirus products, persisting across reboots, and requesting device administrator privileges to hinder removal. Osservatorio Nessuno linked this spyware to IPS Intelligence, an Italian lawful interception company, and assessed likely Italian origins based on source-code clues and infrastructure.
Separately, Morpheus is also referenced as a ransomware strain/group active in 2025-2026. SentinelLABS reported that Morpheus and HellCat operated as distinct brands deploying essentially identical ransomware binaries, differing mainly in the data leak site and contact email, indicating rebranding within the RaaS ecosystem. Proofpoint and third-party researchers reported TransferLoader infections leading to Morpheus ransomware, and assessed Morpheus as likely an updated version of HellCat ransomware. Morpheus was also named in a 2026 extortion incident involving HDFC AMC, where an entity calling itself Morpheus claimed to have exfiltrated more than 680 GB of data and later listed the victim on its onion leak site under the name "HDFC FUND." Because the provided content conflates spyware and ransomware under the same name, attribution and naming should be handled carefully.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2026-0073 is a critical no-interaction remote code execution vulnerability in Android adbd’s ADB-over-TCP authentication path... it is an authentication bypass that lets a remote peer become an authorized ADB host and open a shell as the Android shell user.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TransferLoader malware, which later launches the Morpheus and Metasploit ransomware strains.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Once the spyware was installed, it abused Android’s in-built accessibility features, which allows the spyware to read the data on the victim’s screen and interact with other apps.
It forces users to grant dangerous permissions, including Accessibility access, which allows it to read screens, interact with apps, and capture sensitive data.
Once the spyware was installed, it abused Android’s in-built accessibility features, which allows the spyware to read the data on the victim’s screen and interact with other apps.
It forces users to grant dangerous permissions, including Accessibility access, which allows it to read screens, interact with apps, and capture sensitive data.
It can trick victims into approving actions like linking a WhatsApp account by showing a fake biometric prompt.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named extortion/ransomware operation that allegedly stole 680 GB of HDFC AMC data and threatened publication via a Tor-based leak site. The article characterizes it as a data-extortion-only operation that may pressure victims through leak-site listings rather than necessarily encrypting files.
Android spyware delivered via fake update apps and SMS phishing links impersonating an ISP. It uses a dropper and hidden second-stage payload, abuses Accessibility and overlay permissions, enables Wireless Debugging and ADB pairing, disables security tools, gains persistence across reboots, and supports covert surveillance including audio/video recording, WhatsApp device pairing, evidence erasure, and weakening device protections.
Android spyware linked by researchers to IPS, an Italian lawful-interception vendor. It is delivered via fake Android/update apps, abuses Android accessibility features, steals broad device data, and can gain access to WhatsApp by spoofing the app and tricking the victim into biometric approval for device linking.
Android spyware that abuses Accessibility workflows to enable Developer options, turn on wireless debugging, and locally pair with adbd. The content explicitly states it did not use CVE-2026-0073.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.