Uptime Hamster: 10d 19h 11mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza cephalus

cephalus

2 incidentes 1 paises 2 sectores ransomware Ultimo: 2026-06-29
Ver en IntelTracker → APTTrail →
Cephalus is a ransomware group that emerged in mid-2025, operating with a clear financial motivation. This group distinguishes itself by leveraging stolen Remote Desktop Protocol (RDP) credentials to deploy a custom Go-based ransomware payload. A unique characteristic of Cephalus is its use of DLL sideloading, specifically abusing a legitimate SentinelOne executable to load its malicious code. The group follows a double-extortion model, encrypting data while also exfiltrating sensitive information, which it then publishes on a dedicated dark web leak site to pressure victims into paying. The name Cephalus, derived from a figure in Greek mythology known for an unerring spear, reflects the group's confidence in its targeted approach, primarily impacting sectors such as law firms, healthcare, financial services, IT companies, and manufacturing in regions including the US, Japan, UK, and Netherlands.

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteupransomware.anggipradana.comRansomware Group: cephalus
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (2)

Paises objetivo (SOCRadar)

United KingdomIrelandJapanNetherlandsUnited States

Sectores atacados

Software (1) Healthcare (1)

Sectores objetivo (SOCRadar)

Construction of BuildingsOther Information ServicesSoftware PublishersReal EstateHospitalsManufacturingConstructionElectrical Equipment, Appliance, and Component ManufacturingPublic AdministrationSpace & Defense

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com