Skip to main content
Mallory
MalwareUsed by 1 actorExploits 1 CVE

Morpheus

Morpheus is an Android spyware family publicly reported by Osservatorio Nessuno in 2026. It is distributed through fake Android applications masquerading as phone update or service-restoration apps, including campaigns in which victims received SMS links to ISP-themed phishing sites. The infection chain uses a first-stage dropper to install a hidden second-stage payload that disguises itself as legitimate Android system components with fake names and icons.

The spyware relies on social engineering and abuse of Android permissions rather than root exploits. It pressures victims to grant Accessibility access and uses Accessibility to read screens, interact with apps, and capture sensitive data. During a fake update and fake reboot workflow, it abuses overlay windows and SYSTEM_ALERT_WINDOW, disables touchscreen interaction with a full-screen overlay, enables Developer Options, turns on Wireless Debugging, and pairs locally with the ADB daemon. Using this ADB access, Morpheus silently grants itself sensitive permissions and increases control over the device. Reporting explicitly states that Morpheus did not use CVE-2026-0073 for this behavior.

Reported capabilities include theft of extensive data from infected devices, long-term covert surveillance, audio and video recording, manipulation of WhatsApp device linking, and erasure of evidence on the device. It can display a fake biometric prompt to trick victims into approving WhatsApp account linking. Morpheus also disables or weakens security protections, including camera and microphone indicators, Google Play Protect, Google SafetyCore, and multiple antivirus products such as Bitdefender, Sophos, Avast, AVG, and Malwarebytes. It persists across reboots, can request device administrator privileges, and modifies system settings across Android versions to maintain persistence and hinder removal.

The reporting assesses likely Italian origins based on source-code language clues, infrastructure, and corporate linkages. Osservatorio Nessuno linked Morpheus to IPS Intelligence, an Italian lawful interception company, and described this as the first known public report connecting that firm to spyware distribution and operation. Additional reporting said researchers believed some targeting was related to political activism in Italy. Infrastructure details mentioned in the reporting include encrypted configurations, Italian-hosted servers, and domains linked to small ISPs and obscure entities.

Separate 2025 reporting also uses the name Morpheus for a ransomware strain. Proofpoint and SentinelLABS stated that TransferLoader infections were reported to lead to Morpheus ransomware, and SentinelLABS assessed Morpheus and HellCat ransomware as distinct brands deploying identical payloads, with Morpheus likely an updated version of HellCat. Because the provided content contains two distinct malware usages under the same name, the best-supported and most detailed identification here is the Android spyware family.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2026-0073Authentication Bypass in Android adbd Wireless ADB TLS Verification

CVE-2026-0073 is a critical no-interaction remote code execution vulnerability in Android adbd’s ADB-over-TCP authentication path... it is an authentication bypass that lets a remote peer become an authorized ADB host and open a shell as the Android shell user.

via barghestbarghest.asia
THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
UNK_GreenSec

TransferLoader malware, which later launches the Morpheus and Metasploit ransomware strains.

via scworldscworld.com
MITRE ATT&CK

Techniques & procedures

15 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1566PhishingEvidence1

the telecom provider sent the target an SMS, prompting them to install an app that was supposed to help them update the phone, and regain cellular data access.

T1566.002Spearphishing LinkEvidence1

In this case, targets received an SMS linking to a site impersonating an ISP.

Execution

1 technique
T1204User ExecutionEvidence1
TacticExecution

Attackers used a typical low-cost spyware tactic: disrupt a service and trick the victim into installing a fake app to restore it.

Persistence

4 techniques
T1546Event Triggered ExecutionEvidence1

Once the spyware was installed, it abused Android’s in-built accessibility features, which allows the spyware to read the data on the victim’s screen and interact with other apps.

T1546.008Accessibility FeaturesEvidence1

It forces users to grant dangerous permissions, including Accessibility access, which allows it to read screens, interact with apps, and capture sensitive data.

T1547Boot or Logon Autostart ExecutionEvidence1

The malware also gains persistence by restarting after reboot and can request device admin privileges, making removal difficult.

T1556Modify Authentication ProcessEvidence1

It can trick victims into approving actions like linking a WhatsApp account by showing a fake biometric prompt.

T1546Event Triggered ExecutionEvidence1

Once the spyware was installed, it abused Android’s in-built accessibility features, which allows the spyware to read the data on the victim’s screen and interact with other apps.

T1546.008Accessibility FeaturesEvidence1

It forces users to grant dangerous permissions, including Accessibility access, which allows it to read screens, interact with apps, and capture sensitive data.

T1547Boot or Logon Autostart ExecutionEvidence1

The malware also gains persistence by restarting after reboot and can request device admin privileges, making removal difficult.

T1548Abuse Elevation Control MechanismEvidence2

Osservatorio Nessuno’s April 2026 report on Morpheus describes Android spyware abusing Accessibility workflows to enable Developer options, turn on wireless debugging, and locally pair with adbd.

Stealth

2 techniques
T1036MasqueradingEvidence2
TacticStealth

The second stage disguises itself as legitimate system components, using fake icons and names to appear trustworthy.

T1070Indicator RemovalEvidence1
TacticStealth

Morpheus is extremely invasive: it can record audio and video, silently pair a WhatsApp device, erase evidence, and deliberately weaken the security of the infected phone, among other malicious capabilities.

T1556Modify Authentication ProcessEvidence1

It can trick victims into approving actions like linking a WhatsApp account by showing a fake biometric prompt.

Credential Access

3 techniques
T1056Input CaptureEvidence2

It can trick victims into approving actions like linking a WhatsApp account by showing a fake biometric prompt.

T1556Modify Authentication ProcessEvidence1

It can trick victims into approving actions like linking a WhatsApp account by showing a fake biometric prompt.

T1649Steal or Forge Authentication CertificatesEvidence1

Unbeknownst to the target, the biometric tap granted the spyware full access to their WhatsApp account by adding a device to the account.

Collection

3 techniques
T1056Input CaptureEvidence2

It can trick victims into approving actions like linking a WhatsApp account by showing a fake biometric prompt.

T1123Audio CaptureEvidence1

Morpheus is extremely invasive: it can record audio and video, silently pair a WhatsApp device, erase evidence, and deliberately weaken the security of the infected phone, among other malicious capabilities.

T1125Video CaptureEvidence1

Morpheus is extremely invasive: it can record audio and video, silently pair a WhatsApp device, erase evidence, and deliberately weaken the security of the infected phone, among other malicious capabilities.

Other

1 technique
T1562Impair DefensesEvidence1

In the third phase the spyware disables a number of known Antivirus software, including Google’s own SafetyCore, Bitdefender, Sophos, Avast, AVG, Malwarebytes, along with a handful of smaller cleaner/antivirus apps.

ACTIVITY FEED

Recent activity

8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping15

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.