Morpheus emerged in late 2024 as a semi-private RaaS operation whose affiliates share identical payloads with the HellCat ransomware group, targeting pharmaceutical, manufacturing, legal, and Italian ESXi environments with ransom demands reaching up to 32 BTC (~$3M USD).
Which sectors does the Morpheus group primarily target?+
The Morpheus group targets the Professional Services, Manufacturing, Financial Services, and Technology sectors.
What should defenders focus on regarding the Morpheus ransomware group?+
Defenders should focus on keeping backups offline, enforcing access controls on ESXi servers, and monitoring for IOCs linked to HellCat ransomware activity.