Skip to content
Cephalus Ransomware Targets Windows via Exposed RDP in Double-Extortion Scheme

Cephalus Ransomware Targets Windows via Exposed RDP in Double-Extortion Scheme

First seen 12 Feb 2026, 00:29 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

Cephalus ransomware has been actively exploiting exposed Remote Desktop Protocol (RDP) vulnerabilities since mid-2025, primarily targeting Windows systems. The attacks utilize a double-extortion tactic, where victims are not only encrypted but also threatened with data leaks unless a ransom is paid.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 203d ago How this analysis works

Timeline

2025-06-15
Cephalus ransomware first identified in attacks
2025-07-20
Double-extortion tactics reported
2026-02-11
Latest report on Cephalus ransomware published

More articles in this cluster (1)

Following this threat?

Track Cephalus in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed