Skip to content
Cephalus Ransomware Targets Windows Networks with Double Extortion

Cephalus Ransomware Targets Windows Networks with Double Extortion

First seen 11 Feb 2026, 19:30 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

Cephalus is a Go-based ransomware strain that has been linked to victim activity since June 2025, with public awareness rising in August 2025. It employs a double-extortion tactic, stealing sensitive data before encrypting files, impacting operational continuity for affected organizations. Victims face threats of data leaks alongside operational downtime.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 203d ago How this analysis works

Timeline

2025-06-01
Victim activity linked to Cephalus ransomware begins
2025-08-01
Wider public reporting on Cephalus ransomware
2026-02-11
Cephalus ransomware reported by multiple cybersecurity news outlets

More articles in this cluster (1)

Following this threat?

Track Cephalus in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed