Zeppelin is Windows ransomware derived from the Delphi-based Vega malware family and distributed through a ransomware-as-a-service affiliate model. Advertised under the Zeppelin name in November 2019, it has been used against businesses and critical infrastructure organizations, including defense contractors, educational institutions, manufacturers, technology companies, and particularly healthcare and medical organizations. The malware encrypts files, appends randomized hexadecimal identifiers to their names, and leaves ransom notes demanding payment. Multiple executions within the same victim environment can produce distinct identifiers and require several separate decryption keys.
Zeppelin can be deployed as an executable, a DLL, or through a PowerShell loader. Associated intrusion campaigns have used phishing and spearphishing, abused RDP access, and exploited SonicWall firewall vulnerabilities. Hancitor has also delivered Zeppelin through malicious-document infection chains. In December 2019, attackers compromised a managed service provider and abused ConnectWise Control to distribute Zeppelin to downstream customers. Operators have typically enumerated victim networks and stolen sensitive information before encryption, using potential disclosure or sale of that information as additional leverage.
Vice Society deployed Zeppelin against Windows systems during 2021 and 2022, including in campaigns affecting education and healthcare organizations. Some Vice Society-associated samples masqueraded as legitimate Windows processes, and observed payloads deleted their own executables after execution. Zeppelin samples have also been protected with Rex3Packer to hinder detection and analysis.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Exploiting publicly available vulnerabilities (such as PrintNightmare) to perform remote code execution seems to be the most advanced technique the group has been observed using. | Sekoia investigations show they are currently leveraging the Zeppelin ransomware targeting Windows systems... The Zeppelin samples masquerade as legitimate Windows processes and seem to be linked to the PrintNightmare vulnerability exploitation.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Instead, the actors have deployed versions of Hello Kitty/Five Hands and Zeppelin ransomware, but may deploy other variants in the future.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The author of the publication describes the ransomware functionalities, including... scanning of all local drives and all available network paths
102 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
49 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as ransomware historically associated with VICE SPIDER and SystemBC usage.
Mentioned in passing as a ransomware operation that has run an affiliate program.
Named ransomware family referenced as one of the third-party payloads used by Vice Society.
A third-party ransomware locker delivered in Vice Society attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.