Skip to content

cephalus

Inactive

19 tracked victims · First seen Jun 28, 2025 · Last seen Aug 29, 2025

About

Aggregated threat-intel description

Cephalus is a ransomware group active from mid-2025 that leverages stolen RDP credentials to deploy a Go-based ransomware payload via DLL sideloading, targeting law firms, healthcare, financial services, and IT firms across the US and Japan with 19 known victims.

Sectors: Healthcare, Financial Services, Business Services · Countries: US, GB, IE

Recent victims

View all →
VictimSectorCountryPostedStatus
One-LUXNot FoundGBAug 29, 2025
ShropdocHealthcareGBAug 29, 2025
Shelbourne AccountantsFinancial ServicesIEAug 29, 2025
Delta Information SystemsTechnologyUSAug 29, 2025
Colorado Health Network IncHealthcareUSAug 28, 2025
Texas Pregnancy Care NetworkHealthcareUSAug 28, 2025
wilderlawfirmNot FoundAug 28, 2025
CoCo YachtsManufacturingNLAug 28, 2025
txpregnancy.org - Fake Abortion Clinics ExposedNot FoundUSAug 26, 2025
Town of Vienna, VAPublic SectorUSAug 26, 2025
Lewis Baach Kaufmann Middlemiss PLLCBusiness ServicesUSAug 26, 2025
Lee & AssociatesNot FoundUSAug 26, 2025
Sherman, Silverstein, Kohl, Rose & Podolsky, P.A.Not FoundUSAug 26, 2025
Guerrero Mears LLPNot FoundUSAug 26, 2025
LPL FinancialFinancial ServicesUSAug 26, 2025
K Strategies Marketing and Public RelationsBusiness ServicesUSAug 26, 2025
BAR Architects & InteriorsConstructionAug 26, 2025
SystemExec Co., Ltd.Not FoundAug 26, 2025
CareSTL HealthHealthcareUSAug 26, 2025

All ransomware groups · Dark web intelligence