Description Summary
Zeppelin is a ransomware-as-a-service derived from the Delphi-based Vega/VegaLocker (Buran) family, active from 2019 to 2022. It targeted a range of sectors with a preference for technology and healthcare, exfiltrated data before encryption, and was notable for operators running the encryptor multiple times on a host (nested encryption). It is the subject of CISA advisory AA22-223A; a weakness in its key handling later enabled a decryptor.
Threat Actor
RaaS (Vega/Buran/Delphi lineage); data exfiltration plus double extortion.
Technical Indicators
Encryption Extension
Random 9-hex-digit extension (e.g. .C59-E0C-929)
Encryption Algorithm
AES-256 (files) + RSA-2048 (key wrapping)
Ransom Note Name
!!! ALL YOUR FILES ARE ENCRYPTED !!!.TXT
Targeted Industries
Technology, Healthcare, Defense contractors, Manufacturing, Nonprofit
First Seen
November 2019
Last Seen
2022 (decryptor enabled by a key-handling flaw)
Geographical Location
United States, Europe
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 4 | T1566 | Phishing |
| T1190 | Exploit Public-Facing Application | |
| T1133 | External Remote Services (RDP) | |
| T1078 | Valid Accounts | |
| Exfiltration x 1 | T1567.002 | Exfiltration to Cloud Storage |
| Impact x 2 | T1486 | Data Encrypted for Impact (multiple/nested) |
| T1490 | Inhibit System Recovery |