Cephalus Ransomware
TrackedThreat actor group tracked in the global ransomware database ยท Last disclosure: Aug 29, 2025
ThreatAI Analysis
Compiled from the ransomware.live profile for Cephalus and from this database. Figures and technique mappings are quoted from the source data, not inferred.
Cephalus is a ransomware gang targeting key sectors in multiple countries with 19 recorded victims across fifteen states including US and five countries like Japan.
Who Cephalus is
Cephalus is a ransomware group active from mid-2025 that leverages stolen RDP credentials to deploy a Go-based ransomware payload via DLL sideloading, targeting law firms, healthcare, financial services, and IT firms across the US and Japan with 19 known victims.
Recorded activity
Disclosures attributed to Cephalus in this database run from August 2025 to August 2025, totalling 19 victims โ 0.1% of everything tracked here. Cephalus has listed victims in 5 countries in this database, most often United States, followed by United Kingdom and Japan. The sectors appearing most in its listings are Business Services, Healthcare, Technology.
Indicators of compromise
- 46.17.42.64
Showing a sample of 1 IP on file. Hashes and network indicators published for Cephalus. Leak-site addresses are deliberately excluded. Indicators age quickly โ treat a match as a starting point for investigation, and an absence of matches as no assurance.
YARA detection rules
cephalus.yar
/*
cephalus ransomware
*/
rule cephalus_Ransomnote
{
meta:
author = "ransomware.live"
family = "ransomware.cephalus"
description = "Detects cephalus ransomware ransom note or artifact"
date = "2026-05-04"
severity = 7
score = 70
strings:
$name1 = "cephalus" ascii nocase
$name2 = "CEPHALUS" ascii
$onion = "cephalus.onion" ascii nocase
condition:
any of them
}
Community-contributed rules for Cephalus, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.
Threat Actor Analysis
Cephalus is a ransomware threat group that has disclosed 19 victims in publicly accessible leak site data, representing 0.1% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Cephalus in our dataset dates to August 2025.
Geographically, Cephalus has targeted organisations in 5 countries. The most frequently targeted nation is United States with 13 victim organisations. Other heavily targeted nations include United Kingdom, Japan, Netherlands.
Industry-wise, Cephalus shows a concentration in the Business Services, Healthcare, Technology sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime โ conditions that increase ransom payment likelihood.
Like most modern ransomware operations, Cephalus likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.
Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 19 most recent of the 19 disclosures we hold for this group; use the link beneath it to page through all of them.
Recent Victim Disclosures (showing 19 of 19)
| # | Organization | Country | Sector | Date |
|---|---|---|---|---|
| 1 | Delta Information Systems acroamatics.com | ๐บ๐ธ United States | Technology | Aug 29, 2025 |
| 2 | One-LUX one-lux.com | ๐ฌ๐ง United Kingdom | โ | Aug 29, 2025 |
| 3 | Shelbourne Accountants shelbourneaccountants.ie | ๐ฎ๐ช Ireland | Financial Services | Aug 29, 2025 |
| 4 | Shropdoc shropdoc.org.uk | ๐ฌ๐ง United Kingdom | Healthcare | Aug 29, 2025 |
| 5 | CoCo Yachts www.cocoyachts.com | ๐ณ๐ฑ Netherlands | Manufacturing | Aug 28, 2025 |
| 6 | Colorado Health Network Inc coloradohealthnetwork.org | ๐บ๐ธ United States | Healthcare | Aug 28, 2025 |
| 7 | Texas Pregnancy Care Network texaspregnancy.org | ๐บ๐ธ United States | Healthcare | Aug 28, 2025 |
| 8 | wilderlawfirm wilderlawfirm.com | ๐บ๐ธ United States | โ | Aug 28, 2025 |
| 9 | BAR Architects & Interiors bararch.com | โ | Construction | Aug 26, 2025 |
| 10 | CareSTL Health carestlhealth.org | ๐บ๐ธ United States | Healthcare | Aug 26, 2025 |
| 11 | Guerrero Mears LLP gmllp.com | ๐บ๐ธ United States | Business Services | Aug 26, 2025 |
| 12 | K Strategies Marketing and Public Relations kstrategies.com | ๐บ๐ธ United States | Business Services | Aug 26, 2025 |
| 13 | Lee & Associates lee-irvine.com | ๐บ๐ธ United States | Business Services | Aug 26, 2025 |
| 14 | Lewis Baach Kaufmann Middlemiss PLLC lbkmlaw.com | ๐บ๐ธ United States | Business Services | Aug 26, 2025 |
| 15 | LPL Financial balancedsolutions4me.com | ๐บ๐ธ United States | Financial Services | Aug 26, 2025 |
| 16 | Sherman, Silverstein, Kohl, Rose & Podolsky, P.A. sskrplaw.com | ๐บ๐ธ United States | Business Services | Aug 26, 2025 |
| 17 | SystemExec Co., Ltd. system-exe.co.jp | ๐ฏ๐ต Japan | Technology | Aug 26, 2025 |
| 18 | Town of Vienna, VA viennava.gov | ๐บ๐ธ United States | Public Sector | Aug 26, 2025 |
| 19 | txpregnancy.org - Fake Abortion Clinics Exposed txpregnancy.org | ๐บ๐ธ United States | โ | Aug 26, 2025 |
Frequently Asked Questions
What is Cephalus ransomware?
Cephalus is a ransomware threat group that has claimed 19 victims since its first known activity in August 2025. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.
How many victims has Cephalus attacked?
Cephalus has claimed 19 victims in our database, representing 0.1% of all tracked ransomware attacks. The most targeted countries are United States, United Kingdom, Japan, Netherlands.
Which countries does Cephalus target?
Cephalus has attacked organizations in 5 countries. The top targeted countries are: United States, United Kingdom, Japan, Netherlands.
Which industries does Cephalus target?
Cephalus most frequently targets the Business Services, Healthcare, Technology sectors based on victim disclosures in our database.
Is Cephalus still active?
Cephalus's most recent victim disclosure in our database was on August 29, 2025. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.