{"id":6454,"date":"2025-08-27T10:03:29","date_gmt":"2025-08-27T10:03:29","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/27\/new-cephalus-ransomware-leverages-remote-desktop-protocol-to-gain-initial-access\/"},"modified":"2025-08-27T10:03:29","modified_gmt":"2025-08-27T10:03:29","slug":"new-cephalus-ransomware-leverages-remote-desktop-protocol-to-gain-initial-access","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/27\/new-cephalus-ransomware-leverages-remote-desktop-protocol-to-gain-initial-access\/","title":{"rendered":"New Cephalus Ransomware Leverages Remote Desktop Protocol to Gain Initial Access"},"content":{"rendered":"<p>    New Cephalus Ransomware Leverages Remote Desktop Protocol to Gain Initial Access<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A newly identified ransomware strain named Cephalus has emerged as a sophisticated threat, targeting organizations through compromised Remote Desktop Protocol (RDP) connections.<\/p>\n<p>The malware, which takes its name from Greek mythology referencing the son of Hermes who tragically killed his wife with an infallible javelin, represents a concerning evolution in ransomware deployment techniques.<\/p>\n<p>Cephalus distinguishes itself from other ransomware families through its unique infection methodology and sophisticated evasion tactics.<\/p>\n<p>The malware operators gain initial access to target networks by exploiting RDP credentials that lack <a href=\"https:\/\/cybersecuritynews.com\/microsoft-multi-factor-authentication-issue\/\" target=\"_blank\" rel=\"noreferrer noopener\">multi-factor authentication<\/a> (MFA), a vulnerability that continues to plague organizations worldwide.<\/p>\n<p>Once inside the network, attackers utilize the MEGA cloud storage platform for <a href=\"https:\/\/cybersecuritynews.com\/cl0p-ransomware-data-exfiltration-vulnerable\/\" target=\"_blank\" rel=\"noreferrer noopener\">data exfiltration<\/a> before deploying the ransomware payload.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgleYYCid-8U54o99dxBd15cr0NDt0Xs5OMFQFGs9i0irStabCc47fSSVqnnNnmEoFssQSM7yeYTkcUZ6VAPrmAlvihte9XALbUuGy18szlI5fs-SQUGEkS7gqxa_USLyA4E422k4CarHAXqF_H-O7o1vJTFtInATzutYHWGSlRYJOLoKPubZ_hNs0loKw\/s16000\/Process%2520lineage%2520showing%2520use%2520of%2520MEGA%2520%28Source%2520-%2520Huntress%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Process lineage showing use of MEGA (Source \u2013 Huntress)<\/figcaption><\/figure>\n<\/div>\n<p>The ransomware deployment mechanism involves a particularly clever approach using DLL sideloading through legitimate security software components.<\/p>\n<p>Huntress analysts <a href=\"https:\/\/www.huntress.com\/blog\/cephalus-ransomware\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> this technique during investigations of two separate incidents occurring on August 13 and August 16, 2025, where the malware successfully infiltrated organizations running legitimate SentinelOne security products.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-dll-sideloading-and-execution-chain\"><strong>DLL Sideloading and Execution Chain<\/strong><\/h2>\n<p>The most technically intriguing aspect of Cephalus lies in its deployment strategy, which exploits a legitimate SentinelOne executable file called <code>SentinelBrowserNativeHost.exe<\/code>.<\/p>\n<p>The ransomware operators place this legitimate binary in the user\u2019s Downloads folder, from where it loads a malicious DLL named <code>SentinelAgentCore.dll<\/code>.<\/p>\n<p>This DLL subsequently loads a file called <code>data.bin<\/code> containing the actual ransomware code, creating a multi-stage execution chain that helps evade detection.<\/p>\n<p>Upon successful execution, Cephalus immediately begins system recovery prevention by running embedded commands.<\/p>\n<p>The first command executed is <code>vssadmin delete shadows \/all \/quiet<\/code>, which eliminates volume shadow copies that could be used for file recovery.<\/p>\n<p>The malware then systematically disables <a href=\"https:\/\/cybersecuritynews.com\/windows-defender-enhancements\/\" target=\"_blank\" rel=\"noreferrer noopener\">Windows Defender<\/a> through a series of PowerShell commands that create exclusions for critical system processes and file extensions including .cache, .tmp, .dat, and .sss files.<\/p>\n<p>The ransomware further modifies Windows Registry entries to disable real-time protection, behavior monitoring, and on-access protection features.<\/p>\n<p>It stops and disables Windows Defender services including SecurityHealthService, Sense, WinDefend, and WdNisSvc through PowerShell commands executed with hidden window styles and bypassed execution policies.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEggSpjfdMM7ms1jb0DtMIjrce4zBbXa190lshVM6uWcX861eTIHadR_pGbNzgULNKN2BTOY9EDOTgUkH0a5ZObqrV7q2a8AB93K8TPSp1b4-SQb8-Mj5oqRrfJQq7TmZqp2-4JZ0eyRZmocEWmC4TV5n8q9Ua24ZZyEU4AxdrBKcxDpMCw6O5cEd0DuAEw\/s16000\/Cephalus%2520ransom%2520note%2520posted%2520publicly%2520on%2520Twitter%2520%28Source%2520-%2520Huntress%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Cephalus ransom note posted publicly on Twitter (Source \u2013 Huntress)<\/figcaption><\/figure>\n<\/div>\n<p>Cephalus ransom notes contain a unique characteristic \u2013 they reference news articles about previous successful attacks, attempting to establish credibility and create urgency for victims.<\/p>\n<p>The malware encrypts files with the .sss extension and creates recover.txt files containing payment instructions.<\/p>\n<p>Organizations can protect themselves by implementing MFA for RDP access, monitoring for unauthorized use of legitimate security tool executables in unusual locations, and maintaining comprehensive endpoint detection capabilities.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong><code>Boost\u00a0your\u00a0SOC and help your team protect your business with free top-notch threat intelligence:\u00a0<a href=\"https:\/\/intelligence.any.run\/plans\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=alert_fatigue&amp;utm_content=lookup_plan&amp;utm_term=120825\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Request TI Lookup Premium Trial<\/a>.<\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-cephalus-ransomware-leverages-remote-desktop-protocol\/\">New Cephalus Ransomware Leverages Remote Desktop Protocol to Gain Initial Access<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-cephalus-ransomware-leverages-remote-desktop-protocol\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Cephalus Ransomware Leverages Remote Desktop Protocol to Gain Initial Access A newly identified ransomware strain named Cephalus has emerged as a sophisticated threat, targeting organizations through compromised Remote Desktop Protocol (RDP) connections. The malware, which takes its name from Greek mythology referencing the son of Hermes who tragically killed his wife with an infallible [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-6454","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6454"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6454"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6454\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6454"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6454"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6454"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}