Named After the “Never-Missing Spear”: Cephalus Ransomware Analysis

Summary
Cephalus Information
- A new ransomware group that first appeared in mid-June 2025
- Describes itself as operating with a purely financial motive
- Performs double extortion by leaking targeted organizational data and then encrypting it
- Gains entry by stealing RDP accounts that do not have multi-factor authentication (MFA) enabled
- Targets various countries and industries, including the eastern United States, Japan, the United Kingdom, and sectors such as legal, finance, IT, and government agencies
About the Ransomware
- Developed in Go
- Disrupts analysis by using a fake AES key-generation routine
- Applies techniques to prevent encryption keys from being exposed in memory or on disk
- Appends the .sss extension after encrypting files and creates a ransom note named recover.txt
- Stops services related to backups (Veeam) and databases (MSSQL, MongoDB)
- Modifies Windows Defender settings (diagnostic exclusions, disabling real-time protection, etc.)
Overview
Cephalus
Cephalus is a new ransomware group that first appeared in mid-June 2025. The group claims that they are motivated 100% by financial gain. Their main method of breaching organizations is by stealing credentials through Remote Desktop Protocol (RDP) accounts that do not have multi-factor authentication (MFA) enabled. Their operation is unique in that they have a form of customized ransomware that targets specific organizations, breaches them, exfiltrates their data, and then encrypts it. As of now, it is not yet known if they operate as Ransomware as a Service (RaaS) or if they have formed alliances with other ransomware groups. The name of the group comes from Cephalus, a character in Greek mythology who received an "unerring" spear from Artemis. This is seen as a sign of the group's confidence in their success rate.
There is currently no information available on the rebranding history of the group or their clear and direct connection with other ransomware groups. There is also no information available on the existence of new strains or subgroups. Upon breaching the system, the group openly states their presence and previous cases of damage in their ransom notes to pressure the victims. They also use tactics such as proving the data breach by providing a link to a GoFile repository.
The cases identified so far are concentrated primarily in the United States. Organizations targeted include law firms in the eastern states such as New Jersey and Virginia, as well as architecture offices, financial companies, marketing and PR firms, and local government agencies. Cases have also been reported outside the United States—such as Japanese IT companies and healthcare service providers in the United Kingdom—showing that the group is targeting a wide range of regions and industries.
