The ransomware clones of HellCat & Morpheus. [Research Saturday] episode artwork

EPISODE · Mar 15, 2025 · 18 MIN

The ransomware clones of HellCat & Morpheus. [Research Saturday]

from CyberWire Daily · host N2K Networks

Jim Walter, Senior Threat Researcher on SentinelLabs research team, to discuss their work on "HellCat and Morpheus | Two Brands, One Payload as Ransomware Affiliates Drop Identical Code." Over the past six months, new ransomware groups like FunkSec, Nitrogen, and Termite have emerged, while established threats such as Cl0p and LockBit 4.0 have resurfaced. Two prominent Ransomware-as-a-Service (RaaS) operations, HellCat and Morpheus, have gained traction, with research indicating that affiliates of both are using nearly identical ransomware payloads. Despite similarities in their encryption techniques and ransom notes, there is no conclusive evidence linking HellCat and Morpheus to the Underground Team, though shared tools or affiliates may be involved. The research can be found here: HellCat and Morpheus | Two Brands, One Payload as Ransomware Affiliates Drop Identical Code

Episode metadata supplied by the publisher feed · Published Mar 15, 2025

Embed this episode

NOW PLAYING

The ransomware clones of HellCat & Morpheus. [Research Saturday]

0:00 18:40

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of CyberWire Daily?

This episode is 18 minutes long.

When was this CyberWire Daily episode published?

This episode was published on March 15, 2025.

Can I download this CyberWire Daily episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!