AttackIQ A.I CyberSecurity Scoring
AttackIQ
Company Information
Website:https://attackiq.com
Employees number:193
Number of followers:51,379
NAICS:541514
Industry Type:Computer and Network Security
Homepage:attackiq.com
AttackIQ Risk Score (AI oriented)
Between 650 and 699
AttackIQComputer and Network Security
Updated:
28/03/2026
28/03/2026
662/1000
Weak
B
AttackIQ Global Score (TPRM)
xxxx
AttackIQComputer and Network Security
Score locked

AttackIQWeak
Current Score
662B (WEAK)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
670
JULY 2026
669
JUNE 2026
667
MAY 2026
665
APRIL 2026
664
MARCH 2026
661
FEBRUARY 2026
659
JANUARY 2026
658
DECEMBER 2025
656
NOVEMBER 2025
654
OCTOBER 2025
652
SEPTEMBER 2025
650
JUNE 2025
753
Ransomware
01 Jun 2025 • AttackIQ
Cephalus: Cephalus Ransomware Emerges as Go-Based Double-Extortion Threat Targeting Exposed RDP
Cephalus Ransomware Emerges as a Go-Based Threat Targeting Windows Networks
642
CRITICAL-111
ATT1770818084
Cephalus Ransomware Emerges as a Go-Based Threat Targeting Windows Networks
A new ransomware strain, Cephalus, written in Go, has been active since at least June 2025, with broader public reporting surfacing in August 2025. The malware targets Windows networks, employing a double-extortion tactic stealing sensitive data before encrypting files to pressure victims into paying ransoms. Attackers often leak small "proof" datasets to demonstrate their access, amplifying operational disruptions.
Initial intrusions have been linked to exposed Remote Desktop Protocol (RDP) services lacking multi-factor authentication (MFA), frequently paired with stolen credentials. Once inside, Cephalus moves rapidly, disabling defenses and crippling recovery options. It uses a hybrid encryption scheme, combining AES-256 in CTR mode for file encryption with RSA-1024 to secure per-victim keys.
Researchers at AttackIQ mapped Cephalus’s deployment patterns into an emulation sequence, drawing from reports by Huntress (August 2025) and AhnLab (December 2025), alongside internal analysis. The malware’s tactics, techniques, and procedures (TTPs) include:
- Process injection via `VirtualAlloc` and `VirtualProtect`.
- Persistence through scheduled tasks (`schtasks`).
- Environment reconnaissance using Windows APIs (`GetSystemInfo`, `GetUserNameW`, `CreateToolhelp32Snapshot`).
- File system enumeration with `FindFirstFileW` and `FindNextFileW`.
- Defense evasion, notably tampering with Microsoft Defender disabling real-time protection, adding exclusions, and modifying registry keys via PowerShell (`Add-MpPreference`, `Set-MpPreference`).
Cephalus’s rapid execution and focus on disabling security controls make it a formidable threat, particularly against organizations with unsecured RDP access or weak credential hygiene. The ransomware’s ability to bypass defenses and disrupt recovery underscores the need for proactive monitoring of high-risk entry points.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for AttackIQ ??
What was AttackIQ's A.I Rankiteo Cyber Score in July 2026 ??
What was AttackIQ's A.I Rankiteo Cyber Score in June 2026 ??
What was AttackIQ's A.I Rankiteo Cyber Score in May 2026 ??
What was AttackIQ's A.I Rankiteo Cyber Score in April 2026 ??
What was AttackIQ's A.I Rankiteo Cyber Score in March 2026 ??
What was AttackIQ's A.I Rankiteo Cyber Score in February 2026 ??
What was AttackIQ's A.I Rankiteo Cyber Score in January 2026 ??
What was AttackIQ's A.I Rankiteo Cyber Score in December 2025 ??
What was AttackIQ's A.I Rankiteo Cyber Score in November 2025 ??
What was AttackIQ's A.I Rankiteo Cyber Score in October 2025 ??
What was AttackIQ's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on AttackIQ's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with AttackIQ ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view AttackIQ's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?