Ransomware Group intelligence
Morpheus
ActiveTrack Morpheus with 29 published victims and 1 known leak locations in a single intelligence view.
Overview
Morpheus is tracked by Breach House as a ransomware group with 29 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 1h ago | izsp6ipui4ctgxfugbgtu65kzefrucltyfpbxplmfybl5swiadpljmyd.onion |
Top Activity Sectors (10)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Morpheus, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
What they do: morpheus exploits valid local accounts harvested during initial access to maintain persistence.
What that means: Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1059.001 PowerShell Execution
What they do: morpheus executes malicious payloads via PowerShell scripts injected into legitimate processes.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: morpheus disables antivirus tools by terminating security processes and modifying Windows Defender settings.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1688 Safe Mode Boot Defense Impairment
What they do: morpheus boots into Safe Mode to disable real-time protection before executing encryption routines.
What that means: Adversaries may abuse Windows safe mode to disable endpoint defenses.
-
T1027.002 Software Packing Stealth
What they do: morpheus packs its malware binaries to evade static detection by security tools.
What that means: Adversaries may perform software packing or virtual machine software protection to conceal their code.
-
T1135 Network Share Discovery Discovery
What they do: morpheus scans network shares using net share commands to identify victim data for exfiltration.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: morpheus moves laterally across the network by exploiting SMB shares to access additional systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: morpheus exfiltrates stolen data via encrypted channels before deploying ransomware to maximize pressure.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: morpheus encrypts victim files using strong symmetric encryption before demanding ransom payments.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: morpheus halts system recovery processes by terminating backup services and disabling restore mechanisms.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
_README_.txt
Your network has been breached and all data were encrypted. It can be restored to their original state with a decryptor key that only we have. Warning: 1. Do NOT modify encrypted files yourself. 2. Do NOT use third-party software to restore your data. 3. Do NOT hire a recovery company. They can not decrypt without out private key. 4. Do NOT reboot or turn off storage media. If you do not contact us within 3 days, or we cannot reach an agreement, informati on will either be sold, or shared with the media We have already downloaded a huge amount of critical data. Tags of downloaded information: - Confidential docs - Sales data - Finance documents - Business Plans - Resume - Personal data of employees - Oracle, Microsoft sql database backups - Full Gitlab backup - Tech data (network scheme, Remote Desktop Manager backup, etc.) Sources of information: 10.0.2.98 10.0.26.5 10.0.26.14 10.0.26.19 10.0.26.102 10.0.26.103 10.0.26.105 10.0.76.61 10.0.26.20 Total size of downloaded data: 110 GB You will not only receive a decryptor, but also a description of your network vulnerabilities and information security recommendations. If necessary, you will be provided with qualified data recovery assistance. As a proof of our statements, we are ready to restore some files for free and demonstrate how our product works. We guarantee that our negotiations will remain confidential. Contacts: Onion: izsp6ipui4ctgxfugbgtu65kzefrucltyfpbxplmfybl5swiadpljmyd.onion/ Login: [snip] Password: [snip] Mail: [email protected]
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (29)
Search, filter and paginate the victim timeline for Morpheus. Showing 1–29 of 29.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Yue Ki Industrial id31041 View details | Taiwan, Province of China | Manufacturing / Engineering | — | |
|
Yueki.com.tw is a company based in Taiwan, operating in the manufacturing and engineering sector. The company likely provides various products and services related to its sector, although specific details are not readily available. Yueki.com.tw was listed as a ransomware victim associated with morpheus |
|||||
| Ransomware | Yue Ki Industrial id31041 View details | Taiwan, Province of China | Manufacturing / Engineering | — | |
|
**Website**: yueki.com.tw **Revenue**: $21 Million Yue Ki Industrial is a manufacturing company that creates high-quality industrial products for businesses. They work with metal, plastic, and other |
|||||
| Ransomware | Kyowa Singapore Pte Ltd id30726 View details | Singapore | Manufacturing / Engineering | — | |
|
Kyowa Singapore Pte Ltd is a company based in Singapore, operating in the manufacturing and engineering sector. The company likely provides various products and services related to its sector. Kyowa Singapore Pte Ltd was listed as a ransomware victim associated with morpheus. |
|||||
| Ransomware | Kyowa Singapore Pte Ltd id30726 View details | Singapore | Manufacturing / Engineering | — | |
|
**Website**: kyowasingapore.com **Revenue**: $15 Million Founded in 1979 and headquartered at Benoi Road, Singapore, they primarily supply global consumer electronics, grooming, and automotive indus |
|||||
| Ransomware | Hansa Research Group Pvt. Ltd id30290 View details | India | Communication / Marketing | — | |
|
Hansa Research Group Pvt. Ltd is a research organization based in India, operating in the communication and marketing sector. The company provides research services to its clients. Hansa Research Group Pvt. Ltd was listed as a ransomware victim associated with morpheus. |
|||||
| Ransomware | Hansa Research Group Pvt. Ltd id30290 View details | India | Communication / Marketing | — | |
|
**Website**: hansaresearch.com **Revenue**: $22 Million Hansa Research is a global, full-service market research and consumer insights agency. They help companies make data-driven decisions by provi |
|||||
| Ransomware | Delegal Poindexter & Underkofler, P.A. id30018 View details | United States | Finance / Legal / Insurance | — | |
|
Delegal Poindexter & Underkofler, P.A. is a law firm based in the United States, operating within the finance and legal sectors. The firm provides various legal services to its clients. Delegal Poindexter & Underkofler, P.A. was listed as a ransomware victim associated with morpheus. |
|||||
| Ransomware | Delegal Poindexter & Underkofler, P.A. id30018 View details | United States | Finance / Legal / Insurance | — | |
|
**Website**: protectingcareers.com **Revenue**: $5 Million Delegal Poindexter & Underkofler provides highly specialized legal services to employees with employment law concerns.They represent profes |
|||||
| Ransomware | HDFC FUND id29721 View details | India | Finance / Legal / Insurance | — | |
|
**Website**: hdfcfund.com **Revenue**: $427.8 Million HDFC Asset Management Company Limited (HDFC AMC) is a leading publicly traded investment manager in India, operating as the asset management arm |
|||||
| Ransomware | 3I INFOTECH id29688 View details | India | IT | — | |
|
**Website**: 3i-infotech.com **Revenue**: $96.8 Million 3i Infotech, incorporated in 1993 as 'ICICI Investors Services Limited' and initially an ICICI subsidiary until 2002, is an Indian public glob |
|||||
| Ransomware | BAYTECH A/S id29144 View details | Denmark | Manufacturing / Engineering | — | |
|
**Website**: baytech.dk **Revenue**: $5 Million Baytech A/S is a Danish industrial engineering company that provides crane systems, material handling equipment, and logistics solutions for industria |
|||||
| Ransomware | GGI id28714 View details | Finance / Legal / Insurance | — | ||
|
**Website**: ggitokiomarine.com **Website**: ggipinsurance.com **Revenue**: $19.2 Million Provides comprehensive general and life insurance solutions, including motor, fire, marine, and specialized |
|||||
| Ransomware | SBCTANZANIA id27724 View details | Tanzania, United Republic of | Manufacturing / Engineering | — | |
|
**Website**: sbctanzania.co.tz **Revenue**: $42.5 Million SBC Tanzania Limited, established in 2001, is a prominent beverage manufacturer and distributor in Tanzania, dedicated to producing PepsiCo |
|||||
| Ransomware | SURTECHINC id26887 View details | Korea, Republic of | IT | — | |
|
**Website**: surtechinc.kr **Revenue**: $5 Million Company is a leader in the plating industry, leveraging our accumulated experience and technological prowess to provide the highest quality and ser |
|||||
| Ransomware | SUNSETWORLDRESORTS id25908 View details | Mexico | Hospitality / Food & Beverage / Tourism | — | |
|
**Website**: sunsetworldresorts.com **Revenue**: $593 Million Sunset World Group is a Mexican family business founded by some of the pioneers of Cancun who helped turn it into the most sought-after |
|||||
| Ransomware | VALLEREDONDO id25157 View details | Spain | Other | — | |
|
**Website**: valleredondo.com.mx **Revenue**: $50 Million Family owned, founded in 1964 by Don Luis Ferruccio Cetto, right in the center of México, in Aguascalientes. With more than 60 years special |
|||||
| Ransomware | SCIPIONI id24715 View details | Belgium | Energy | — | |
|
**Website**: scipioni.be **Revenue**: $5 Million Scipioni is a company specializing in the distribution of petroleum products since 1974. Located in the Charleroi region.Scipioni is a company that s |
|||||
| Ransomware | Teamglobal id24021 View details | India | Manufacturing / Engineering | — | |
|
Website: teamglobal.com Revenue: $6.3 Million Premier contract and direct hire staffing services. 30 years of industry experience in aerospace and light industrial and an extensive client list. ** |
|||||
| Ransomware | Landmark Properties id20145 View details | United States | Communication / Marketing | — | |
|
**Website**: landmarkproperties.com **Revenue**: $1.5 Billion Landmark Properties is a fully integrated real estate firm specializing in development, construction, management, investment, and consul |
|||||
| Ransomware | Metal Sales Manufacturing Corporation id19022 View details | United States | Manufacturing / Engineering | — | |
|
**Website**: metalsales.us.com **Revenue**: $270.1 Million Metal Sales is the largest manufacturer of metal roofing, wall, and building systems in the United States, also offering metal fabrication |
|||||
| Ransomware | Latronica Law Firm, P.C id18967 View details | United States | Finance / Legal / Insurance | — | |
|
**Website**: latronicalaw.com **Revenue**: $5 Million The Latronica Law is a firm specializing in personal injury/negligence cases, criminal defense, and divorce/family law, with a focus on maximizi |
|||||
| Ransomware | New_publication id18946 View details | Public Sector | — | ||
|
New_publication is listed in the Public Sector, a category that includes government-owned or government-funded organizations serving public needs at local, regional, or national levels. Public-sector bodies commonly provide essential civic services, administrative functions, and other non-profit public functions on behalf of the state. No reliable public source in the provided results identifies New_publication’s exact location or service portfolio, so this listing is kept intentionally general. It was listed as a ransomware victim associated with morpheus. |
|||||
| Ransomware | New publication id18931 View details | Public Sector | — | ||
|
Baytech A/S is a prominent Danish provider of material handling and logistics solutions operating within the Public Sector industrial landscape. The company specializes in delivering critical infrastructure support for manufacturing and supply chain operations across Europe. Its offerings include comprehensive logistics systems designed to enhance operational efficiency for mid-sized engineering firms. On May 14, 2026, the Morpheus ransomware group claimed Baytech A/S as a victim on the dark web, utilizing double-extortion tactics. Baytech A/S was listed as a ransomware victim associated with the Morpheus threat actor. |
|||||
| Ransomware | Alora Pharmaceuticals, LLC id18894 View details | United States | Healthcare / Pharma | — | |
|
**Website**: alorapharma.com acellapharma.com avionrx.com osmotica.com sovpharm.com trigenlab.com verticalpharma.com **Revenue**: $337.4 Million Alora Pharmaceuticals, LLC is a parent company of si |
|||||
| Ransomware | Dinizulu Law Group LTD id17778 View details | United States | Finance / Legal / Insurance | — | |
|
**Website**: dinizululawgroup.com **Revenue**: $5 Million Dinizulu Law Group, Ltd is a personal injury law firm based in Chicago, dedicated to achieving the best outcomes for clients through a compa |
|||||
| Ransomware | DZL id17756 View details | IT | — | ||
|
[AI generated] DZL is a global software company that provides library management solutions. Their products assist in managing, digital resource acquisition, cataloguing, circulation, and administration. Their proven software, known as "Liberty" and "Eclipse", is used by a wide variety of academic, public and corporate libraries and information centers worldwide. |
|||||
| Ransomware | LYNXSPA id16698 View details | Spain | Services | — | |
|
**Website**: lynxspa.com **Revenue**: $292.5 Million Lynx, the Partner for Digital Transformation The Lynx Group specialises in the design and implementation of digital solutions, supporting large o |
|||||
| Ransomware | Arrotex Pharmaceuticals id16528 View details | Australia | Healthcare / Pharma | — | |
|
Website: https://dbghealth.com.au/arrotex/ Revenue: $92 Million The extent of the **cybersecurity incident** is not completely revealed in the published [article](https://dbghealth.com.au/important- |
|||||
| Ransomware | Pus Gmbh id16527 View details | Germany | Services | — | |
|
**Website**: pus-gmbh.eu **Revenue**: $5 Million The P&S GmbH & Co. KG has specialized as a manufacturer of electronic products and solutions for the time management. Time management includes time r |
|||||