Ransomware group
Morpheus ransomware: victims and leak site activity
The Morpheus ransomware group has listed 23 victims on its leak site since January 2025; its latest post is from 30 July 2026. Most affected countries: United States, India and Spain. Most targeted sector: Professional Services.
Total posts
23
First seen
2025-01-07
Latest post
2026-07-30
Countries hit
12
About Morpheus
Morpheus emerged in late 2024 as a semi-private RaaS operation whose affiliates share identical payloads with the HellCat ransomware group, targeting pharmaceutical, manufacturing, legal, and Italian ESXi environments with ransom demands reaching up to 32 BTC (~$3M USD).
Most targeted countries
- United States 6
- India 4
- Spain 2
- Australia 1
- Belgium 1
- Germany 1
- Denmark 1
- South Korea 1
- Mexico 1
- Singapore 1
Most targeted sectors
- Professional Services 7
- Manufacturing 4
- Technology 3
- Agriculture and Food Production 2
- Financial Services 2
- Healthcare 2
- Energy & Utilities 1
- Hospitality 1