Cephalus Ransomware Emerges as Go-Based Double-Extortion Threat Exploiting Exposed RDP Access
ID: c1c03ad9-30b7-5215-b1c2-dfb675fbaa28
STIX ID: report--c1c03ad9-30b7-5215-b1c2-dfb675fbaa28
Feed Name: GBHackers
Cephalus is a Go-based ransomware campaign active since mid-2025 that leverages exposed RDP and stolen credentials for initial access, uses process injection and anti-analysis techniques, encrypts files with AES-256 CTR and protects keys with RSA-1024, and conducts data exfiltration to cloud services (e.g., MEGA) followed by public leak-site extortion; it also disables Defender, deletes Volume Shadow Copies, and terminates backup/database services to maximize impact, with guidance recommending removal of public RDP, enforcing MFA, and verifying backups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
