Ransomware Group intelligence
Cephalus
InactiveTrack Cephalus with 19 published victims and 3 known leak locations in a single intelligence view.
Overview
Cephalus is tracked by Breach House as a ransomware group with 19 published victims.
United States is currently the most targeted country in this dataset.
3 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (3)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Down checked 57m ago | cephalus6oiypuwumqlwurvbmwsfglg424zjdmywfgqm4iehkqivsjyd.onion |
| File host (third party) | Third-party file host | Down checked 57m ago | darkforums.st |
| Leak location 1 | Web location | Down checked 57m ago | 46.17.42.64. |
Top Activity Sectors (7)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Cephalus, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: cephalus uses PowerShell scripts to execute malicious commands and deploy ransomware payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1106 Native API Execution
What they do: cephalus leverages native API calls to interact with system functions for execution and evasion during initial compromise.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
What they do: cephalus establishes persistence by modifying registry run keys to ensure malware execution on system startup.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: cephalus disables antivirus tools and security software to prevent detection and ensure successful ransomware deployment.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: cephalus encodes and encrypts its own malware binaries to evade signature-based detection systems.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: cephalus deletes Volume Shadow Copies and backup files using system commands to prevent data recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1049 System Network Connections Discovery Discovery
What they do: cephalus discovers network connections to identify high-value targets and establish command-and-control channels.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: cephalus moves laterally through SMB shares to access additional victim machines within the network.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: cephalus encrypts victim files using strong symmetric cryptography to maximize impact and ransom demand.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: cephalus inhibits system recovery by corrupting critical system files and disabling repair mechanisms.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (19)
Search, filter and paginate the victim timeline for Cephalus. Showing 1–19 of 19.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | One-LUX id22024 View details | United Kingdom | Other | — | |
|
coming soon |
|||||
| Ransomware | Shropdoc id22023 View details | United Kingdom | Other | — | |
|
coming soon |
|||||
| Ransomware | Shelbourne Accountants id22022 View details | Ireland | Other | — | |
|
coming soon... |
|||||
| Ransomware | Delta Information Systems id22021 View details | United States | IT | — | |
|
We have got all the software and hardware code,and got 800G+ of internal data. The link will coming soon... Of if anyone is intersted in purchasing the code,pls contact me |
|||||
| Ransomware | Colorado Health Network Inc id21995 View details | United States | Healthcare / Pharma | — | |
|
900G+ data coming soon |
|||||
| Ransomware | Texas Pregnancy Care Network id21994 View details | United States | Communication / Marketing | — | |
|
coming soon |
|||||
| Ransomware | wilderlawfirm id21993 View details | United States | Finance / Legal / Insurance | — | |
|
coming soon |
|||||
| Ransomware | CoCo Yachts id21992 View details | Netherlands | Communication / Marketing | — | |
|
We got a total of 1.8TB+ of data,including project,clients,employee information,and a certain country's naval ship design..... The data link will coming soon |
|||||
| Ransomware | txpregnancy.org - Fake Abortion Clinics Exposed id21965 View details | United States | Communication / Marketing | — | |
|
coming soon |
|||||
| Ransomware | Town of Vienna, VA id21964 View details | United States | Other | — | |
|
coming soon |
|||||
| Ransomware | Lewis Baach Kaufmann Middlemiss PLLC id21963 View details | United States | Finance / Legal / Insurance | — | |
|
coming soon |
|||||
| Ransomware | Lee & Associates id21962 View details | United States | Other | ||
|
Lee & Associates DATA LEAK | (TB) |
|||||
| Ransomware | Sherman, Silverstein, Kohl, Rose & Podolsky, P.A. id21961 View details | United States | Finance / Legal / Insurance | ||
|
SSKRPLAW DATA LEAK | (5GB+ ZIP) |
|||||
| Ransomware | Guerrero Mears LLP id21960 View details | United States | Other | ||
|
Guerrero Mears LLP DATALEAK | (FORGOT THE SIZE) |
|||||
| Ransomware | LPL Financial id21959 View details | United States | Finance / Legal / Insurance | ||
|
LPL Financial DATA LEAK | (I FORGOT THE SIZE,BUT ITS HUGE) |
|||||
| Ransomware | K Strategies Marketing and Public Relations id21958 View details | United States | Communication / Marketing | ||
|
K Strategies Marketing and Public Relations LEAK | 900+GB |
|||||
| Ransomware | BAR Architects & Interiors id21957 View details | Hospitality / Food & Beverage / Tourism | |||
|
BAR Architects & Interiors DATA LEAK | 1.5T+ |
|||||
| Ransomware | SystemExec Co., Ltd. id21956 View details | Japan | Services | ||
|
SystemExec Co., Ltd. (システムエグゼ) GitLab naked repo leak | 30G+ |
|||||
| Ransomware | CareSTL Health id21955 View details | United States | Healthcare / Pharma | ||
|
CareSTL Health DATA Leak | 500+GB | KAWA4096 STEALED our data |
|||||