Cephalus is a ransomware group active since mid-2025, known for using stolen RDP credentials and DLL sideloading.
Analyst brief
Cephalus is a ransomware group active since mid-2025 that primarily uses stolen RDP credentials for initial access. The group targets law firms, healthcare, financial services, and IT companies across the US and Japan. They deploy a Go-based ransomware payload via DLL sideloading as a key TTP. Defenders should focus on hardening RDP authentication and monitoring for DLL sideloading anomalies.
cephalus
crime
Cephalus is a ransomware group active from mid-2025 that leverages stolen RDP credentials to deploy a Go-based ransomware payload via DLL sideloading, targeting law firms, healthcare, financial services, and IT firms across the US and Japan with 19 known victims.