Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Morado

Morado Vendor Cyber Rating & Cyber Score

morado.io

There is more cyber threat intelligence available today than ever before, but the challenge is knowing what is actionable and having the tools to act on it. Morado surfaces the intelligence that matters most and turns it into outcomes. Our platform, Threatnote, is a Unified Threat Management Platform that puts Intel Operations and native Threat Intelligence Platform capabilities at the center. On top of that, it unifies dark web monitoring, brand protection, and third-party risk intelligence into a single solution built for both enterprises and MSSPs. With everything standardized in STIX format and connected workflows, teams can collect, enrich, and act on intelligence in one place. Combined with our advisory expertise, we help


Morado A.I CyberSecurity Scoring

Morado
Company Information
Website:http://www.morado.io
Employees number:12
Number of followers:1,652
NAICS:
Industry Type:Information Technology & Services
Homepage:morado.io
Morado Risk Score (AI oriented)
Between 650 and 699
logo
MoradoInformation Technology & Services
Updated:
21/03/2026
660/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Morado Global Score (TPRM)
xxxx
logo
MoradoInformation Technology & Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Morado
MoradoWeak
Current Score
660B (WEAK)
01000
2 incidents
-80 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
666Before Incident
MAY 2026
663Before Incident
APRIL 2026
663Before Incident
MARCH 2026
659Before Incident
FEBRUARY 2026
737Before Incident
Breach
01 Feb 2026Morado
WormGPT: AI hacking platform WormGPT has user data leaked, attackers claim

WormGPT AI Hacking Platform Suffers Data Breach, Exposing 19,000 Users

657After Incident
CRITICAL-80
MOR1770718261
WormGPT AI Hacking Platform Suffers Data Breach, Exposing 19,000 Users A malicious AI tool designed for cybercrime, WormGPT, has allegedly suffered a data breach, exposing the personal details of 19,000 users. The leak, posted on a popular data breach forum earlier this month, includes sensitive information such as payment details, subscription plans, and user identities, raising concerns about targeted attacks against its customers. WormGPT, launched as a ChatGPT alternative for cybercriminals, offers subscription-based access starting at $50 per month or a $220 lifetime plan. The platform enables users even those without advanced hacking skills to conduct malware development, DDoS attacks, social engineering, and system infiltration. Its Telegram channel openly promotes illicit activities, including password cracking and crypto wallet hacking. The leaked data, verified by researchers, includes email addresses, payment currencies, and plan types, which could be exploited for phishing campaigns, blackmail, or identity discovery. The breach also highlights the risks of blackhat AI tools, as users of WormGPT may now face retaliation from other cybercriminals. The incident follows a pattern of malicious AI services being targeted by attackers, underscoring the growing threat of AI-driven cybercrime and the vulnerabilities of underground platforms.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Payment details, subscription plans, user identities, email addresses, payment currencies, plan typesIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Payment detailsSubscription plansUser identitiesEmail addressesPayment currenciesPlan typesNumber Of Records Exposed: 19,000Sensitivity Of Data: HighPersonally Identifiable Information: Yes
JANUARY 2026
737Before Incident
DECEMBER 2025
736Before Incident
NOVEMBER 2025
736Before Incident
OCTOBER 2025
736Before Incident
SEPTEMBER 2025
735Before Incident
AUGUST 2025
734Before Incident
JULY 2025
734Before Incident
MAY 2025
752Before Incident
Cyber Attack
23 May 2025Morado
Mamona: DragonForce Engages in "Turf War" for Ransomware Dominance

DragonForce's Turf War and Hostile Takeover of RansomHub

733After Incident
CRITICAL-19
MOR1766630178
DragonForce Escalates Cybercrime Turf War, Disrupts RansomHub and Rivals A new report from Sophos reveals that the ransomware group DragonForce is waging a “turf war” against rival operators as it seeks to dominate the cybercrime marketplace. The group’s aggressive expansion—including a hostile takeover attempt—may have contributed to RansomHub’s infrastructure outage in late March 2025, leading to a notable drop in ransomware attacks in April. ### DragonForce’s Cartel Model and Expansion In March 2025, DragonForce rebranded as a ransomware cartel, adopting a RaaS (Ransomware-as-a-Service) syndicate model that allows affiliates to operate under their own brands while leveraging DragonForce’s infrastructure. The group introduced “RansomBay”, a white-label service enabling affiliates to rebrand its ransomware tools. In exchange, DragonForce takes a 20% cut of ransom payments, providing affiliates with technical support, leak-site hosting, and operational backing. This model has already seen use in high-profile attacks, including those by Scattered Spider against UK retailers Marks & Spencer (M&S), the Co-operative Group, and Harrods in late April 2025. ### Attacks on Competing RaaS Groups Sophos researchers noted that DragonForce’s cartel announcement in March coincided with defacements of leak sites operated by rival groups BlackLock and Mamona, both of which were replaced with DragonForce’s logo. The move signals an aggressive push to undermine competitors and consolidate control over the ransomware ecosystem. The disruption of RansomHub and the broader decline in ransomware activity suggest DragonForce’s tactics may be reshaping the cybercrime landscape—at least temporarily.
INCIDENT DETAILS -
TYPE
Ransomware, Cyber Turf War, Infrastructure Disruption
MOTIVATION
Dominance in cybercrime marketplace, Financial gain, Expansion of RaaS operations
IMPACT
Systems Affected: RansomHub infrastructure, BlackLock and Mamona leak sitesDowntime: Significant (RansomHub outage in late March 2025)Operational Impact: Decline in ransomware attacks in April 2025, Disruption of rival RaaS operationsBrand Reputation Impact: Negative for affected RaaS groups (e.g., RansomHub, BlackLock, Mamona)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Morado ?
?
What was Morado's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Morado's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Morado's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Morado's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Morado's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Morado's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Morado's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Morado's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Morado's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Morado's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Morado's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Morado's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Morado ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Morado's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?