logo

Cephalus Ransomware: Don’t Lose Your Head

ID: bcf86d59-9b09-5c83-a1c2-785473b007d9

STIX ID: report--bcf86d59-9b09-5c83-a1c2-785473b007d9

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2025-08-21

Date Updated: 2026-04-28

...
...

**Executive summary:** Huntress describes two mid‑August incidents involving the Cephalus ransomware that gained initial access via compromised RDP accounts, used MEGA for probable data exfiltration, and deployed ransomware by DLL sideloading through a legitimate SentinelOne binary (SentinelBrowserNativeHost.exe) which loaded a data.bin payload; the activity included disabling Defender, deleting shadow copies, and posting ransom notes with verification links — several IOCs (file names, hashes, extensions, and paths) are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.