Quick Summary
AllegedExecutive Summary
Yue Ki Industrial, a manufacturing company based in Taiwan, has been targeted by the Morpheus ransomware group. The threat actor listed the company on July 30, 2026, as observed by SOCRadar’s Dark Web Monitoring. One recovered credential associated with the incident points to the company’s Enterprise Resource Planning (ERP) portal, a critical system for manufacturing operations. This targeting of an ERP system suggests a potential focus on disrupting production and operational workflows. Morpheus continues to be an active ransomware operation, having claimed five other victims in the preceding 60 days. The group’s recent targeting has shown a lean towards Business Services, Manufacturing, and Financial Services sectors, with a notable geographic footprint across India, Taiwan, and Singapore. While Yue Ki Industrial aligns with the manufacturing industry and the broader Asia-Pacific focus, it breaks the trend of predominantly targeting business services organizations. Previous victims listed by Morpheus include Kyowa Singapore Pte Ltd, Hansa Research Group Pvt. Ltd, Delegal Poindexter & Underkofler, P.A., and HDFC FUND.
Technical Analysis
Threat intelligence indicates a notable credential exposure related to Yue Ki Industrial on the domain yueki[.]com[.]tw. A single credential was recovered, targeting a company ERP portal via an eip. subdomain. The observed username pattern is consistent with an internal employee or system account, suggesting a high risk of corporate intrusion. The timestamp for this credential capture is narrowly focused around mid-June 2026, indicating a recent compromise event. Direct access to an ERP system is particularly significant for a manufacturing company, as these systems are intrinsically linked to operational and production workflows. While only one record was identified in this particular sample, the presence of this credential does not rule out the possibility of additional compromised accounts existing outside of this observed dataset. The operational pattern of the Morpheus ransomware group commonly involves the use of infostealer-harvested credentials as a primary method for initial access. Threat actors or access brokers often acquire recent credential logs, validate corporate credentials that provide access to platforms such as Microsoft 365, VPNs, or remote-access portals, and then proceed with ransomware deployment. The recovered credential for Yue Ki Industrial fits this typical kill chain, although it has not been independently confirmed that Morpheus specifically utilized this credential for their attack. Given the observed credential exposure and the typical modus operandi of the Morpheus group, it is recommended that Yue Ki Industrial takes immediate action. This includes rotating the compromised credential, invalidating active sessions associated with it, and enforcing multi-factor authentication (MFA) on the affected ERP account. Continued monitoring of dark web and stealer-log feeds for further related exposures is also advised.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.