Scworld
Cephalus Ransomware Exploits Stolen RDP Credentials
First seen 2 Dec 2025, 18:33 UTC
•


•86% similarity
•25.8
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Threat actors are leveraging stolen Remote Desktop Protocol (RDP) credentials to deploy Cephalus ransomware. Organizations without multi-factor authentication are particularly vulnerable, as the ransomware is tailored to maximize impact on targeted networks. This operation has been reported by multiple cybersecurity news outlets, highlighting the ongoing risks associated with exposed RDP credentials.
ThreatCluster AI
How this analysis works