Cephalus

Cephalus — Threat Actor Profile | ObscureIQ
ObscureIQ Threat Intelligence · Actor Profile

CephalusConfidence: High

Ransomware

Motivation: Financial

1Attributed Breaches Circulating
HighAttribution Confidence
RansomwareActor Type

Overview

Breaches organizations through stolen RDP credentials on accounts lacking MFA, first seen mid-June 2025 against law firms, healthcare, financial services, and IT across the US and Japan. Deploys a Go-based payload via DLL sideloading through a legitimate SentinelOne executable; states it is 100% financially motivated.

Tactics, Targeting & TTPs

Go-based payload deployed via DLL sideloading through a legitimate SentinelOne executable (SentinelBrowserNativeHost.exe); double extortion. States it is 100% financially motivated.

Source

Attribution draws on public threat-intelligence reporting · Established (multi-source). Primary source →

Were you exposed in one of these breaches?

Check your exposure privately, or request a tailored exposure audit.

Request Consultation