
ThreeAM and Morpheus Ransomware Groups Launch Coordinated Global Attacks in October 2026
New intelligence confirms ThreeAM and Morpheus ransomware groups have targeted critical healthcare and industrial sectors in Colombia and Taiwan, utilizing aggressive double-extortion tactics.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- Global
- Confidence:
- Confirmed
- Source:
- Ransomnews
- Read Time:
- 4 min
Executive Summary
As of October 3, 2026, the global ransomware landscape remains highly volatile. Recent intelligence reports indicate that threat actors ThreeAM and Morpheus have successfully executed high-profile attacks against critical infrastructure providers. These incidents, occurring within the last 48 hours, highlight a persistent trend of targeting essential services to maximize leverage for ransom payments.
Threat Analysis
The ransomware ecosystem in 2026 is characterized by a shift toward specialized, high-impact targeting. ThreeAM has claimed responsibility for an attack on Coosalud EPS, a major healthcare provider in Colombia, while Morpheus has struck Superior Plating Technology Co in Taiwan. Both groups are employing double-extortion strategies, where sensitive data is exfiltrated prior to encryption, forcing victims to negotiate under the threat of public data exposure.
Technical Details
These groups continue to refine their operational security. ThreeAM and Morpheus utilize sophisticated malware variants capable of bypassing traditional endpoint detection. Common tactics observed include the use of shadow copy deletion to prevent recovery, process injection to maintain persistence, and the deployment of Tor-based communication channels for ransom negotiations. Initial access is frequently gained through a combination of phishing campaigns and the exploitation of unpatched internet-facing services.
Attribution Assessment
ThreeAM and Morpheus are identified as financially motivated cybercriminal syndicates operating within the Ransomware-as-a-Service (RaaS) model. Their recent activity aligns with the broader 2026 trend of increased aggression, as documented by security researchers tracking over 850 confirmed incidents this year. These groups are distinct from larger, more established cartels but demonstrate high operational maturity.
Implications
The targeting of healthcare and industrial sectors poses significant risks to public safety and supply chain stability. The shift toward encryption-less extortion and the use of infostealer-fed access pipelines suggest that organizations must move beyond simple backup strategies. The potential for data leaks following these attacks remains a critical concern for affected stakeholders.
Recommendations
Organizations are advised to: 1) Implement robust multi-factor authentication (MFA) across all remote access points. 2) Conduct regular vulnerability assessments, specifically targeting internet-facing infrastructure. 3) Maintain offline, immutable backups to mitigate the impact of encryption. 4) Monitor for indicators of compromise (IoCs) associated with known RaaS affiliates and engage in proactive threat hunting to identify unauthorized lateral movement.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

ThreeAM and Morpheus Ransomware Groups Launch Coordinated Global Extortion Campaigns

Chaos and M3rx Ransomware Groups Escalate Attacks on US Professional and Healthcare Sectors

