Cephalus is a ransomware and extortion group first observed in mid-2025. The operation presents itself as purely financially motivated and has been associated with targeted intrusions that combine unauthorized access, data theft, and file encryption. Known activity indicates the group has operated a leak site and used stolen-data publication threats as leverage, including against healthcare organizations. Cephalus has been linked to initial access via compromised Remote Desktop Protocol accounts, particularly where multi-factor authentication is absent. Reported tradecraft includes credential theft for remote access, targeted victim selection, data exfiltration prior to encryption, and extortion through threats to publish stolen information and contact third parties. Its ransom communications emphasize financial motives, negotiation, and reputational pressure, and threaten disclosure to clients, partners, regulators, and other external parties if payment is not made. The malware attributed to Cephalus has been described as Go-based and engineered to hinder analysis and recovery. Reported behaviors include disabling Microsoft Defender real-time protection, deleting Volume Shadow Copy backups, and stopping services associated with backup and database operations to maximize encryption impact. The ransomware uses AES-CTR for file encryption and protects the encryption material with RSA, while also employing memory-protection and anti-analysis measures intended to reduce key exposure and mislead analysts. Victimology directly tied to observed activity includes the healthcare sector in the United States, where Cephalus claimed responsibility for an intrusion at Colorado Health Network and alleged theft of a large volume of sensitive patient and organizational data. Cephalus was also identified among newly emerged groups contributing to increased ransomware pressure on healthcare organizations during 2025. No high-confidence evidence in the available facts establishes state sponsorship, a ransomware-as-a-service structure, or known sub-groups.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware-linked extortion attack against Colorado Health Network, claiming large-scale data exfiltration and threatening publication of stolen data unless ransom demands were met.
Operated a dark web leak site and claimed to have stolen 900 GB of data from Colorado Health Network (CHN); the group then disappeared from public view days later without leaking the data.
Financially motivated ransomware operations: initial access via stolen RDP credentials (no MFA), followed by data exfiltration and encryption (customized per victim) with pressure tactics including explicit ransom notes and proof-of-breach links (GoFile).
Cephalus is a newly emerged ransomware group contributing to a surge in attacks on the healthcare sector in Q3 2025.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.