Cephas is a phishing kit offered in the phishing-as-a-service ecosystem and observed as a newer entrant in 2025. It is designed to support credential phishing operations with a focus on evasion and validation of stolen access data. Cephas uses obfuscation together with anti-bot and anti-analysis measures to hinder automated inspection and defensive analysis. It integrates with Microsoft APIs to validate captured credentials and session tokens at submission time, allowing operators to confirm that stolen data is usable before acting on it. Reporting also notes unusual page-comment behavior consistent with fingerprinting evasion or content diversification. Cephas is associated with phishing operations rather than a clearly attributed nation-state or named intrusion set, and available information does not support high-confidence attribution to a specific country or operator group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.