logo

The ransomware clones of HellCat & Morpheus.

ID: 19fb5a2a-840f-53a0-8dc8-8513fdc8d484

STIX ID: report--19fb5a2a-840f-53a0-8dc8-8513fdc8d484

Feed Name: The CyberWire

Threat Score
70/100

Date Published: 2025-03-15

Date Updated: 2026-04-23

...
...

SentinelLabs research reports that two Ransomware-as-a-Service operations, HellCat and Morpheus, have affiliates deploying nearly identical ransomware payloads, including similar encryption methods and ransom notes. The analysis notes the emergence of new groups (e.g., FunkSec, Nitrogen, Termite) and the return of established actors (Cl0p, LockBit 4.0) over the past six months, and suggests code/tool sharing or overlapping affiliates as a possible explanation though no definitive link to the Underground Team was established.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.