Morpheus has posted four victim claims in the past month, spanning manufacturing in Taiwan, professional services in Singapore, business services in India, and a US legal firm, indicating an opportunistic rather than sector-specific targeting pattern despite India accounting for the largest share of its all-time claims. The group is described in its own materials as a semi-private RaaS operation sharing payloads with the HellCat ransomware group, with claimed ransom demands reportedly as high as 32 BTC, though these figures should be treated as attacker self-reporting rather than confirmed fact. Given its lineage, affiliates are likely to follow ESXi-focused double-extortion tradecraft similar to HellCat, including exfiltration ahead of encryption and targeting of virtualized server environments to maximize operational disruption. The group's low but steady claim volume since first appearing on tracking in June 2026 suggests a small affiliate base still building out its victim list rather than a high-volume commodity operation.