logo

Cephalus Ransomware Emerges as Go-Based Double-Extortion Threat Exploiting Exposed RDP Access

ID: c1c03ad9-30b7-5215-b1c2-dfb675fbaa28

STIX ID: report--c1c03ad9-30b7-5215-b1c2-dfb675fbaa28

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-02-11

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Cephalus is a Go-based ransomware campaign active since mid-2025 that leverages exposed RDP and stolen credentials for initial access, uses process injection and anti-analysis techniques, encrypts files with AES-256 CTR and protects keys with RSA-1024, and conducts data exfiltration to cloud services (e.g., MEGA) followed by public leak-site extortion; it also disables Defender, deletes Volume Shadow Copies, and terminates backup/database services to maximize impact, with guidance recommending removal of public RDP, enforcing MFA, and verifying backups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.