cephalus
First seen August 26, 2025Active19 claimed victims
The claims below are reproduced as posted by cephalus on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
Cephalus is a ransomware group active from mid-2025 that leverages stolen RDP credentials to deploy a Go-based ransomware payload via DLL sideloading, targeting law firms, healthcare, financial services, and IT firms across the US and Japan with 19 known victims.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| Delta Information Systems | August 29, 2025 | ransomware_live | — |
| Shelbourne Accountants | August 29, 2025 | ransomware_live | — |
| Shropdoc | August 29, 2025 | ransomware_live | — |
| One-LUX | August 29, 2025 | ransomware_live | — |
| CoCo Yachts | August 28, 2025 | ransomware_live | — |
| wilderlawfirm | August 28, 2025 | ransomware_live | — |
| Texas Pregnancy Care Network | August 28, 2025 | ransomware_live | — |
| Colorado Health Network Inc | August 28, 2025 | ransomware_live | — |
| SystemExec Co., Ltd. | August 26, 2025 | ransomware_live | — |
| BAR Architects & Interiors | August 26, 2025 | ransomware_live | — |
| K Strategies Marketing and Public Relations | August 26, 2025 | ransomware_live | — |
| LPL Financial | August 26, 2025 | ransomware_live | — |
| Guerrero Mears LLP | August 26, 2025 | ransomware_live | — |
| Sherman, Silverstein, Kohl, Rose & Podolsky, P.A. | August 26, 2025 | ransomware_live | — |
| Lewis Baach Kaufmann Middlemiss PLLC | August 26, 2025 | ransomware_live | — |
| Town of Vienna, VA | August 26, 2025 | ransomware_live | — |
| txpregnancy.org - Fake Abortion Clinics Exposed | August 26, 2025 | ransomware_live | — |
| Lee & Associates | August 20, 2025 | ransomware_live | — |
| CareSTL Health | June 28, 2025 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).