Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Cephalus

193
Global rank
161 infographic chevron month
Month rank
122 infographic chevron week
Week rank

Cephalus is a targeted ransomware threat discovered in 2025. It’s known for infiltrating organizations that deal with sensitive data through compromised RDP access. It leverages DLL sideloading with a legitimate SentinelOne executable. Cephalus is able to exfiltrate data and destroy backup options. Its payload is also tailored to each victim, which makes identification and mitigation more complex.

Ransomware
Type
Unknown
Origin
1 August, 2025
First seen
30 September, 2026
Last seen

How to analyze Cephalus with ANY.RUN

Type
Unknown
Origin
1 August, 2025
First seen
30 September, 2026
Last seen

IOCs

IP addresses
150.171.109.99
34.107.243.93
52.123.243.201
199.232.210.172
51.75.242.210
2.23.246.9
2.16.204.151
150.171.28.11
34.149.226.178
2.16.204.147
23.11.40.157
149.137.141.9
128.24.231.65
142.251.152.119
48.209.133.15
151.101.129.91
48.192.1.65
45.112.123.126
95.100.102.101
57.153.246.3
Hashes
25f5229d2c05f4883245fe331033b79f2b77dd84296151ae8c59b1ed27e7fe5c
8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903
2b4a47b82cbe70e34407c7df126a24007aff8b45d5716db384d27cc1f3b30707
d2cd0bef5f45daf490c53e705d6f67dfe12390c72a00efa6f5117432bd8edb8c
92b772380a3f8e27a93e57e6deeca6c01da07f5aadce78bb2fbb20de10a66925
b9fa2d52a4ffabb438b56184131b893b04655b01f336066415d4fe839efe64e7
5b462316a51c918d0bae95959bf827cb9c72bbd84ffb0e43b750aa91fbf3ba53
0c9d2b64f35f0c27d1e81fece055a6650da8e6da248dd61aab2942e3eb7d818f
e56bea638916fe77e80a4fadcae78e3ed5526a69033d2d56ef0ca7c479c557bd
059c4b34974649085d66724fc1553c06cf4c18f71ee93fb8bd13d51a6333e8a8
a10254eac725d93aa9d4eaa48b6e6aa4e9b1c4d32a94830746a1b0233c54df63
71c68f8127449bb6ecb1a803239a4e242ba7f7c76e4aaf28b667bee853e30ece
8e95ecc731af4e8a7f3a7066c6dfaf371a3b38829b1ca1b19d8ebac861a77bff
f0d177e0385ce031bcc08d1cf278cb8ce1981571e6d00474e010f3f7e6164354
9eb8ed19e5fb64890244188b4e0daaffd15cbf1495eda1fe8b613f7b99a21a1c
bcff243b1ea4856caa8c49d876a8793686a2d4fddf83e47dc9066f91274e12c1
39a63d56be4f1ca950310f385e8a42f7bc2dcc0e49fefff306176182bfa4f0e5
46028a4bfb6d468d705964267538b6ae1f291411466d20792b346550f88956c2
fb55e26c6a8977b724a0b01e08738ae390cbe37a5264ee8a43393a03d8635e66
c7da5a00a7ed9fe9940d11ffd763412ac638d271b8c93998df8e2d584fd7024e
Domains
msedge.b.tlu.dl.delivery.mp.microsoft.com
settings-win.data.microsoft.com
www.bing.com
ads-img.mozilla.org
api.edgeoffer.microsoft.com
login.live.com
www.microsoft.com
crl.microsoft.com
mozilla.map.fastly.net
content-signature-2.cdn.mozilla.net
s.gofile.io
ecs.office.com
trip.prf.hn
example.org
safebrowsing.googleapis.com
api.gofile.io
firefox.settings.services.mozilla.com
push.services.mozilla.com
tagesschau.de
static.edge.microsoftapp.net
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:jogm5oyi19neiv6btykiu8wt4hebojkhveltvduv2pm&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=at
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://s3.us-east-005.backblazeb2.com/vx-underground-main/malware%20analysis/2025/2025-12-24%20-%20detecting%20and%20responding%20to%20cephalus%20ransomware%20with%20wazuh/samples/a34acd47127196ab867d572c2c6cf2fcccffa3a7a87e82d338a8efed898ca722.7z?x-amz-algorithm=aws4-hmac-sha256&x-amz-credential=005e2c099359ccf0000000004%2f20260930%2fus-east-1%2fs3%2faws4_request&x-amz-date=20260930t104019z&x-amz-expires=3600&x-amz-signedheaders=host&x-amz-signature=d126b745776256034249074bc4d9d89b460b507d1efeebf1daafa6b8abfbb252
https://copilot.microsoft.com/c/api/user/eligibility
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-us&acceptformat=crx3,puff&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d285%2526e%253d1
https://update.googleapis.com/service/update2/json?cup2key=14:qy2tpvrn1gbftl0cqv1eykg4pvddxlwhcs9jkj8hwdw&cup2hreq=848d3391ca5ce9037a908b868ba43d5b2bac865e9ea970ab518e0fc117dfa3f6
https://clients2.googleusercontent.com/crx/blobs/azpvhcqildrgqxyclcenwovmaua7lwu2mln7dephdl7eqkp9gczqmiehkjncu7a_eigr4ip8elijgyg1mgbqewwsojngu_j8zva9cfi_aj--ikwjbypwnpfv9nmzws17bigaxlka5c7tdptpcgaddf44n1nzr3cqv7qk/ghbmnnjooekpmoecnnnilnnbdlolhkhi_1_110_1_0.crx
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://www.bing.com/api/shopping/v1/user/shoppingsettings?enabledservicefeaturesv2=edgeserverux.shopping.cashbackeumarkets,edgeserverux.shopping.msedgeshoppingcashbackdismisstimeout2s
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=edge_hub_apps_manifest_gz&version=4.11.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=domains_config_gz&version=3.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=arbitration_priority_list&version=24.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=1&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
Last Seen at

Recent blog posts

post image
5 Critical Pain Points of Modern US SOCs and...
watchers 1648
comments 0
post image
IronChain Ransomware Threatens Businesses wit...
watchers 3378
comments 0
post image
Threat Coverage Digest: New Malware Reports a...
watchers 10879
comments 0

Cephalus Ransomware: New Threat Abusing Legitimate Files

Key Takeaways

  1. Discovered in mid-2025, Cephalus is a novel ransomware strain targeting organizations across various sectors, including IT, healthcare and finance.
  2. Its attack methods combine the abuse of compromised Remote Desktop Protocol (RDP) credentials with DLL sideloading.
  3. Cephalus applies a targeted approach and tailors malware to their victims, making detection more complex.
  4. Upon infiltration of targeted networks, it deactivates security software and erases backups.
  5. Such a tailored approach and backup erasure make the recovery especially challenging.
  6. Security teams can use ANY.RUN’s Interactive Sandbox to expose Cephalus Ransomware for deep insights into its behavior. View analysis of a Cephalus sample.

Cephalus analysis in Sandbox Cephalus threat analyzed in ANY.RUN’s Interactive Sandbox

  1. Explore Cephalus in TI Lookup to identify and monitor its variants.

Cephalus TTPs in Sandbox Latest reports on Cephalus shown by ANY.RUN's TI Lookup

What Is Cephalus Malware?

Cephalus is a recently observed ransomware threat abusing RDP by stealing credentials, often in systems that lack multi-factor authentication (MFA). That’s how it gains initial access. Once inside, it uses DLL sideloading technique to slip past defenses. As it infiltrates the system, Cephalus encrypts data and prevents its recovery, demonstrating a ransom demand.

The threat's name comes from Greek mythology, referencing a character of the same name with a precise, unerring spear. This suggests an accurate and targeted approach to victims — a fitting analogy, as observed attacks involve tailored malware.

Two notable campaigns took place in August 2025. In both cases, legitimate SentinelOne instances were abused to load a malicious DLL and embed ransomware code.

It’s not entirely known at the moment whether it’s a ransomware-as-a-service or an independent group. Geographic and industrial scopes remain diverse. Among the prevalent targeted sectors are healthcare and finance businesses from the US.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Cephalus Malware Technical Details

The breakdown of how Cephalus typically infiltrates systems:

– Credential theft. Cephalus specifically targets infrastructures where RDP isn’t efficiently protected; this includes the lack of MFA. That’s how threat actors gain initial access.

– Data exfiltration via MEGA cloud storage platform. Before the payload is deployed, threat actors use legitimate RDP accounts to exfiltrate information. Since credentials are legit, this activity doesn’t look suspicious.

– Payload delivery via DLL sideloading. The threat actors abuse legitimate SentinelOne executable, load malicious DLL, and embed malicious code:

  1. Legitimate SentineOne binary is run from the Downloads folder to execute a malicious DLL (SentinelAgentCore.dll).
  2. The binary itself is legitimate (SentinelBrowserNativeHost.exe), which reduces the chance of detection.
  3. The DLL executes data.bin with a ransomware code.

– Evasion and anti-forensics. The ransomware is written in Go (Golang) and uses memory obfuscations.

– Security disabling. Commands like vssadmin destroy shadow copies, registry changes disable Windows Defender, and backup services like Microsoft SQL Server are terminated.

– Exfiltration and encryption. Data is uploaded to MEGA cloud storage and files are encrypted with .sss extension.

– Ransom note. Once the defenses and backup solutions are eliminated, the attackers deploy ransomware by sharing a .txt ransom note in numerous locations.

The note urges the user to begin the negotiation ASAP. In the opposite case, threat actors threaten to leak all data and contact the victim’s clients about their sensitive data being compromised.

Tactics like deletion of shadow copies and registry manipulations to disable security tools make recovery increasingly more complex. The result is stolen data and disrupted operations.

Most notable feature is the unique way to launch the ransomware: through legitimate SentinelOne executable file.

Cephalus Victimology

The scope of victims and their geography is wide. Cephalus targets a number of sectors — IT, healthcare, finance, law firms, etc. What attracts the threat actors is companies that handle sensitive data or intellectual properties, not a particular industry.

Not only large enterprises, but also mid-sized firms are on the list. This might indicate that Cephalus prioritizes smaller companies with weaker security defenses.

Geographically, most attacks are US-based, but there are victims outside the US too.

Cephalus Execution Process

Let's see how Cephalus operates in the ANY.RUN sandbox. Follow this link to see the entire analysis:

View analysis session with Cephalus ransomware

Cephalus TTPs in Sandbox Analysis of Cephalus inside ANY.RUN's Interactive Sandbox

As we can see, upon execution, treat actors collect general info about the victim’s environment. This includes:

– Computer’s name

– Supported languages

– Registry requests

Cephalus TTPs in Sandbox TTPs used by Cephalus to get info on the victim’s system as seen in ANY.RUN's Interactive Sandbox

After that, it begins to encrypt user’s files and does so topically. Such an approach accelerates the process as compared to recursive launch across all user catalogs.

The victim is then shown a ransom note in their infiltrated system. You can see its fragment below:

Cephalus ransom note in Sandbox Cephalus ransom note fragment shown in ANY.RUN’s Interactive Sandbox

The note highlights the urgency of the incident and offers proof of data stealth. It says that confidential data will be leaked, and the victim’s clients will be contacted via calls or emails to inform them about their data being stolen. All this motivates the victim to start the negotiation urgently.

Cephalus also deletes shadow copies using the vssadmin command. This prevents the recovery of the system through VSS. As a result, the chances that the victim will be able to recover data on their own are minimized, once again highlighting the complexity of the situation.

Cephalus Malware Distribution Methods

According to research, Cephalus seems to be mostly distributed through stolen and compromised RDP credentials. They hit infrastructures with exposed RDP, for example, in cases where there is no multi-factor authentication (MFA).

Gathering Threat Intelligence on Cephalus Malware

Threat Intelligence Lookup enables security teams to quickly search for information about suspicious files, URLs, domains, and IP addresses potentially associated with Cephalus.

By querying file hashes or URLs encountered in environments, analysts can immediately determine if they match known Cephalus samples, view detailed behavioral analysis, and understand the specific capabilities and infrastructure of particular variants.

This rapid intelligence access accelerates incident response and enables proactive blocking of threats before they impact systems.

Start exploring any threat by looking it up by the name, for instance:

threatName:"Cephalus"

Cephalus results in Lookup TI Lookup results for Cephalus threats

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Cephalus is a high-impact ransomware threat that abuses legitimate executables to bypass defenses. It terminates backups and copies, making recovery extremely different. The malware targets organizations with sensitive data and weak defenses.

To avoid compromise and start monitoring Cephalus, its new strains, and other threats, apply a proactive approach to security. Analyze suspicious files in sandboxing services like ANY.RUN’s Interactive Sandbox

To track emerging threats and enrich your indicators, try Threat Intelligence Lookup, a browsable collection of IOCs and IOBs gathered from live investigations done by 15,000+ SOC teams.

Sign up to start gathering actionable intel in TI Lookup. Get 50 trial requests

HAVE A LOOK AT

Grandoreiro screenshot
Grandoreiro
grandoreiro
Grandoreiro is a Latin American banking trojan first observed in 2016. It targets mostly Spanish-speaking countries, such as Brazil, Spain, Mexico and Peru. This malware is operated as a Malware-as-a-Service (MaaS), which makes it easily accessible for cybercriminals. Besides, it uses advanced techniques to evade detection.
Read More
Razr screenshot
Razr
razr
Razr is a destructive ransomware that infiltrates systems to encrypt files, rendering them inaccessible to users. It appends the ".razr" extension to the encrypted files and drops a ransom note, typically named "README.txt," instructing victims on how to pay the ransom to obtain the decryption key. The malware often spreads through phishing emails with malicious attachments or by exploiting vulnerabilities in software and operating systems. Razr employs strong encryption algorithms, making it challenging to decrypt files without the attackers' key.
Read More
RondoDox screenshot
RondoDox
rondodox
RondoDox is an emerging Linux-based botnet malware that exploits dozens of known vulnerabilities in internet-facing devices like routers, DVRs, and web servers to build massive networks for DDoS attacks, cryptomining, and data exfiltration. First spotted in mid-2025, its "exploit shotgun" tactic (firing multiple payloads at once) has made it a rapid escalator in the IoT threat landscape, compromising unpatched edge devices worldwide.
Read More
WannaCry screenshot
WannaCry
wannacry ransomware
WannaCry is a famous Ransomware that utilizes the EternalBlue exploit. This malware is known for infecting at least 200,000 computers worldwide and it continues to be an active and dangerous threat.
Read More
HijackLoader screenshot
HijackLoader
hijackloader
HijackLoader is a modular malware acting as a vehicle for distributing different types of malicious software on compromised systems. It gained prominence during the summer of 2023 and has since been used in multiple attacks against organizations from various sectors, including hospitality businesses.
Read More
Ramnit screenshot
Ramnit
ramnit
Ramnit is a highly modular banking trojan and worm that evolved from a file-infecting virus into a powerful cybercrime tool. It specializes in financial fraud, credential theft, remote access, and malware delivery, being a serious threat to businesses and individuals. First spotted in 2010, Ramnit became popular after the 2014 takedown of the GameOver Zeus botnet, as cybercriminals sought alternatives for banking fraud.
Read More