Zeppelin Ransomware

Description Summary

Zeppelin is a ransomware-as-a-service derived from the Delphi-based Vega/VegaLocker (Buran) family, active from 2019 to 2022. It targeted a range of sectors with a preference for technology and healthcare, exfiltrated data before encryption, and was notable for operators running the encryptor multiple times on a host (nested encryption). It is the subject of CISA advisory AA22-223A; a weakness in its key handling later enabled a decryptor.

Threat Actor

RaaS (Vega/Buran/Delphi lineage); data exfiltration plus double extortion.

Technical Indicators

Encryption Extension
Random 9-hex-digit extension (e.g. .C59-E0C-929)
Encryption Algorithm
AES-256 (files) + RSA-2048 (key wrapping)
Ransom Note Name
!!! ALL YOUR FILES ARE ENCRYPTED !!!.TXT
Targeted Industries
Technology, Healthcare, Defense contractors, Manufacturing, Nonprofit
First Seen
November 2019
Last Seen
2022 (decryptor enabled by a key-handling flaw)
Geographical Location
United States, Europe

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 4 T1566 Phishing
T1190 Exploit Public-Facing Application
T1133 External Remote Services (RDP)
T1078 Valid Accounts
Exfiltration x 1 T1567.002 Exfiltration to Cloud Storage
Impact x 2 T1486 Data Encrypted for Impact (multiple/nested)
T1490 Inhibit System Recovery