Cephalus Ransomware Targets Windows via Exposed RDP in Double-Extortion Scheme

Cephalus Ransomware Targets Windows via Exposed RDP in Double-Extortion Scheme

First seen 12 Feb 2026, 00:29 UTC Cyberpress 81% similarity 38.5

Article Content

Browse articles
ThreatCluster

Cephalus ransomware has been actively exploiting exposed Remote Desktop Protocol (RDP) vulnerabilities since mid-2025, primarily targeting Windows systems. The attacks utilize a double-extortion tactic, where victims are not only encrypted but also threatened with data leaks unless a ransom is paid.

ThreatCluster AI How this analysis works

Timeline

2025-06-15
Cephalus ransomware first identified in attacks
2025-07-20
Double-extortion tactics reported
2026-02-11
Latest report on Cephalus ransomware published

Community

Browse all →

Tracked Entities in This Story