Cyberpress
Cephalus Ransomware Targets Windows via Exposed RDP in Double-Extortion Scheme
First seen 12 Feb 2026, 00:29 UTC
•
•81% similarity
•38.5
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Cephalus ransomware has been actively exploiting exposed Remote Desktop Protocol (RDP) vulnerabilities since mid-2025, primarily targeting Windows systems. The attacks utilize a double-extortion tactic, where victims are not only encrypted but also threatened with data leaks unless a ransom is paid.
ThreatCluster AI
How this analysis works
Timeline
2025-06-15
Cephalus ransomware first identified in attacks
2025-07-20
Double-extortion tactics reported
2026-02-11
Latest report on Cephalus ransomware published