Cephalus

Inactive
Cephalus is a ransomware group active from mid-2025 that leverages stolen RDP credentials to deploy a Go-based ransomware payload via DLL sideloading, targeting law firms, healthcare, financial services, and IT firms across the US and Japan with 19 known victims.
19 Victims
Jun 28, 2025 First Discovered
Aug 28, 2025 Last Discovered
384 Days Inactive
0% Infostealer
0/2 Sites Online
Known Locations (2)
Cephalus
46.17.42.64.
Cephalus
cephalus6oiypuwumqlwurvbmwsfglg424zjdmywfgqm4iehkqivsjyd.onion
Victims (19)

Detailed victim list temporarily unavailable

This group has 19 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.