CE

Cephalus Ransomware

Tracked

Threat actor group tracked in the global ransomware database ยท Last disclosure: Aug 29, 2025

Ransomware-as-a-Service (RaaS) Double Extortion Target: Business Services
19
Total Victims
0.1% of all tracked
5
Countries Targeted
7
Sectors Targeted
2025
First Seen

ThreatAI Analysis

Compiled from the ransomware.live profile for Cephalus and from this database. Figures and technique mappings are quoted from the source data, not inferred.

Cephalus is a ransomware gang targeting key sectors in multiple countries with 19 recorded victims across fifteen states including US and five countries like Japan.

Who Cephalus is

Cephalus is a ransomware group active from mid-2025 that leverages stolen RDP credentials to deploy a Go-based ransomware payload via DLL sideloading, targeting law firms, healthcare, financial services, and IT firms across the US and Japan with 19 known victims.

Recorded activity

Disclosures attributed to Cephalus in this database run from August 2025 to August 2025, totalling 19 victims โ€” 0.1% of everything tracked here. Cephalus has listed victims in 5 countries in this database, most often United States, followed by United Kingdom and Japan. The sectors appearing most in its listings are Business Services, Healthcare, Technology.

Indicators of compromise

  • 46.17.42.64

Showing a sample of 1 IP on file. Hashes and network indicators published for Cephalus. Leak-site addresses are deliberately excluded. Indicators age quickly โ€” treat a match as a starting point for investigation, and an absence of matches as no assurance.

YARA detection rules

cephalus.yar
/*
cephalus ransomware
*/

rule cephalus_Ransomnote
{
    meta:
        author = "ransomware.live"
        family = "ransomware.cephalus"
        description = "Detects cephalus ransomware ransom note or artifact"
        date = "2026-05-04"
        severity = 7
        score = 70

    strings:
        $name1 = "cephalus" ascii nocase
        $name2 = "CEPHALUS" ascii
        $onion  = "cephalus.onion" ascii nocase

    condition:
        any of them
}

Community-contributed rules for Cephalus, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.

Threat Actor Analysis

Cephalus is a ransomware threat group that has disclosed 19 victims in publicly accessible leak site data, representing 0.1% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Cephalus in our dataset dates to August 2025.

Geographically, Cephalus has targeted organisations in 5 countries. The most frequently targeted nation is United States with 13 victim organisations. Other heavily targeted nations include United Kingdom, Japan, Netherlands.

Industry-wise, Cephalus shows a concentration in the Business Services, Healthcare, Technology sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime โ€” conditions that increase ransom payment likelihood.

Like most modern ransomware operations, Cephalus likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.

Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 19 most recent of the 19 disclosures we hold for this group; use the link beneath it to page through all of them.

Recent Victim Disclosures (showing 19 of 19)

# Organization Country Sector Date
1 Delta Information Systems acroamatics.com ๐Ÿ‡บ๐Ÿ‡ธ United States Technology Aug 29, 2025
2 One-LUX one-lux.com ๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom โ€” Aug 29, 2025
3 Shelbourne Accountants shelbourneaccountants.ie ๐Ÿ‡ฎ๐Ÿ‡ช Ireland Financial Services Aug 29, 2025
4 Shropdoc shropdoc.org.uk ๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom Healthcare Aug 29, 2025
5 CoCo Yachts www.cocoyachts.com ๐Ÿ‡ณ๐Ÿ‡ฑ Netherlands Manufacturing Aug 28, 2025
6 Colorado Health Network Inc coloradohealthnetwork.org ๐Ÿ‡บ๐Ÿ‡ธ United States Healthcare Aug 28, 2025
7 Texas Pregnancy Care Network texaspregnancy.org ๐Ÿ‡บ๐Ÿ‡ธ United States Healthcare Aug 28, 2025
8 wilderlawfirm wilderlawfirm.com ๐Ÿ‡บ๐Ÿ‡ธ United States โ€” Aug 28, 2025
9 BAR Architects & Interiors bararch.com โ€” Construction Aug 26, 2025
10 CareSTL Health carestlhealth.org ๐Ÿ‡บ๐Ÿ‡ธ United States Healthcare Aug 26, 2025
11 Guerrero Mears LLP gmllp.com ๐Ÿ‡บ๐Ÿ‡ธ United States Business Services Aug 26, 2025
12 K Strategies Marketing and Public Relations kstrategies.com ๐Ÿ‡บ๐Ÿ‡ธ United States Business Services Aug 26, 2025
13 Lee & Associates lee-irvine.com ๐Ÿ‡บ๐Ÿ‡ธ United States Business Services Aug 26, 2025
14 Lewis Baach Kaufmann Middlemiss PLLC lbkmlaw.com ๐Ÿ‡บ๐Ÿ‡ธ United States Business Services Aug 26, 2025
15 LPL Financial balancedsolutions4me.com ๐Ÿ‡บ๐Ÿ‡ธ United States Financial Services Aug 26, 2025
16 Sherman, Silverstein, Kohl, Rose & Podolsky, P.A. sskrplaw.com ๐Ÿ‡บ๐Ÿ‡ธ United States Business Services Aug 26, 2025
17 SystemExec Co., Ltd. system-exe.co.jp ๐Ÿ‡ฏ๐Ÿ‡ต Japan Technology Aug 26, 2025
18 Town of Vienna, VA viennava.gov ๐Ÿ‡บ๐Ÿ‡ธ United States Public Sector Aug 26, 2025
19 txpregnancy.org - Fake Abortion Clinics Exposed txpregnancy.org ๐Ÿ‡บ๐Ÿ‡ธ United States โ€” Aug 26, 2025

Frequently Asked Questions

What is Cephalus ransomware?

Cephalus is a ransomware threat group that has claimed 19 victims since its first known activity in August 2025. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has Cephalus attacked?

Cephalus has claimed 19 victims in our database, representing 0.1% of all tracked ransomware attacks. The most targeted countries are United States, United Kingdom, Japan, Netherlands.

Which countries does Cephalus target?

Cephalus has attacked organizations in 5 countries. The top targeted countries are: United States, United Kingdom, Japan, Netherlands.

Which industries does Cephalus target?

Cephalus most frequently targets the Business Services, Healthcare, Technology sectors based on victim disclosures in our database.

Is Cephalus still active?

Cephalus's most recent victim disclosure in our database was on August 29, 2025. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.