
ThreeAM and Morpheus Ransomware Groups Launch Coordinated Global Extortion Campaigns
As of October 2, 2026, the ThreeAM and Morpheus ransomware groups have targeted critical infrastructure in Colombia and Taiwan, respectively, utilizing double extortion tactics to pressure victims.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- Global
- Confidence:
- Confirmed
- Source:
- Dexpose.io
- Read Time:
- 4 min
Executive Summary
On October 2, 2026, intelligence reports confirmed that two distinct ransomware syndicates, ThreeAM and Morpheus, have initiated high-impact extortion campaigns against international targets. ThreeAM has successfully compromised Coosalud EPS, a major healthcare provider in Colombia, while Morpheus has targeted Superior Plating Technology Co, a prominent industrial firm in Taiwan. These incidents highlight a persistent trend of sector-specific targeting and the continued reliance on double extortion models to maximize leverage over victims.
Threat Analysis
The current threat landscape remains volatile, with August 2026 seeing a record-breaking 1,073 global ransomware incidents. The recent activities of ThreeAM and Morpheus align with the broader trend of RaaS (Ransomware-as-a-Service) groups diversifying their geographic reach. By targeting healthcare and industrial sectors, these groups aim to exploit the high sensitivity of data and the critical nature of operational uptime to force rapid ransom payments.
Technical Details
Both groups are employing sophisticated double extortion techniques. In the case of Coosalud EPS, ThreeAM has threatened to leak sensitive patient health records on their dedicated leak site if demands are not met. Morpheus, targeting the Taiwanese industrial sector, is utilizing custom encryption variants designed to bypass standard endpoint detection and response (EDR) solutions. These groups often gain initial access through exploited software vulnerabilities or credential harvesting, followed by lateral movement to identify and exfiltrate high-value data before deploying the final encryption payload.
Attribution Assessment
ThreeAM continues to operate as a disciplined, financially motivated actor with a focus on healthcare infrastructure. Morpheus, while relatively newer in the current cycle, demonstrates high technical proficiency in targeting industrial control systems and manufacturing environments. Both groups operate under the RaaS model, allowing them to scale operations by leveraging a network of affiliates who handle initial access and post-compromise activities.
Implications
The targeting of healthcare and industrial sectors poses significant risks to public safety and supply chain stability. The use of double extortion—encrypting systems while simultaneously exfiltrating data—ensures that even if a victim restores from backups, the threat of public data exposure remains a potent motivator for payment. Organizations in these sectors must prepare for increased scrutiny and potential follow-on attacks.
Recommendations
Organizations are advised to: 1) Implement robust, air-gapped backup solutions to ensure recovery without paying ransoms. 2) Conduct regular vulnerability assessments and patch management, specifically targeting internet-facing assets. 3) Deploy advanced behavioral monitoring to detect lateral movement and unauthorized data exfiltration. 4) Establish a clear incident response plan that includes communication strategies for potential data breaches.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Chaos and M3rx Ransomware Groups Escalate Attacks on US Healthcare and Legal Sectors

Chaos and M3rx Ransomware Groups Escalate Attacks on US Professional and Healthcare Sectors

