Blogs

HellCat, Morpheus RaaS operations leverage similar payloads

SentinelOne researchers analyzing the HellCat and Morpheus ransomware-as-a-service operations found payloads with almost identical code, despite the groups presenting themselves as separate brands. The samples differed mainly in victim-specific details and the contact information used in their ransom notes, suggesting that affiliates may be using the same builder or a shared codebase.

The analyzed ransomware used the Windows Cryptographic API for encryption and avoided selected system-critical files so an infected machine would remain operational enough to display recovery instructions. Both operations also issued similarly structured ransom notes directing victims to separate Tor portals with supplied credentials.

The overlap is significant for defenders because threat detection should focus on shared technical behavior rather than relying only on a ransomware brand name. However, the researchers cautioned that code similarity alone does not prove that HellCat and Morpheus are run by the same people. It may instead reflect shared tooling, affiliates, or service infrastructure within the ransomware ecosystem.

Original sources

SentinelOne — HellCat and Morpheus: Two Brands, One Payload

SC Media — HellCat and Morpheus RaaS operations leverage similar payloads

Independently summarized and reviewed by CNB Telecom.

Leave a Reply

Your email address will not be published. Required fields are marked *