Cephalus Ransomware Deployed via Stolen RDP Credentials
First seen 8 Nov 2025, 12:36 UTC
•

•94% similarity
•46
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Threat actors are exploiting exposed Remote Desktop Protocol (RDP) credentials to deploy Cephalus ransomware. This attack targets organizations that have not secured their RDP access, leading to potential data breaches and operational disruptions. The exact number of affected entities and the scale of the attack remain unclear.
ThreatCluster AI
How this analysis works