Zeppelin is a Delphi-based ransomware family derived from Vega and operated as a ransomware-as-a-service offering from 2019 through at least mid-2022. It has been used against a broad range of businesses and critical infrastructure organizations, including defense contractors, educational institutions, manufacturers, technology companies, and especially healthcare and medical entities. The malware has also appeared as a third-party locker deployed by other intrusion and extortion actors, notably Vice Society, rather than being exclusive to a single threat group.
Zeppelin is associated with double-extortion operations in which attackers typically obtain access to victim environments, spend time enumerating networks and identifying valuable data stores and backups, exfiltrate sensitive data, and then deploy the encryptor to pressure payment through both operational disruption and threatened publication or sale of stolen information. Investigations have shown that the malware can be delivered and executed in multiple forms, including DLL, EXE, and PowerShell-loaded variants. In some incidents, operators executed Zeppelin multiple times within the same victim environment, producing different victim identifiers and requiring separate decryption keys.
Observed initial access methods associated with Zeppelin intrusions include exploitation of exposed remote access services, exploitation of SonicWall vulnerabilities, phishing and spearphishing, and in Vice Society-linked activity, exploitation of PrintNightmare. Vice Society-linked Zeppelin samples targeting Windows were observed masquerading as legitimate Windows processes. Zeppelin has also been delivered as a downstream payload by other malware, including Hancitor.
The ransomware targets Windows systems. Upon execution it encrypts files and appends a randomized hexadecimal extension, then drops a ransom note on compromised systems. Victimology and operational reporting indicate financially motivated use across multiple sectors, with particularly notable impact on healthcare and education. Law-enforcement reporting has tied the Zeppelin operation to Russian-speaking cybercrime activity, including an affiliate-based business model and later criminal charges against an alleged leader of the group.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Exploiting publicly available vulnerabilities (such as PrintNightmare) to perform remote code execution seems to be the most advanced technique the group has been observed using. | Sekoia investigations show they are currently leveraging the Zeppelin ransomware targeting Windows systems... The Zeppelin samples masquerade as legitimate Windows processes and seem to be linked to the PrintNightmare vulnerability exploitation.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Sekoia investigations show they are currently leveraging the Zeppelin ransomware targeting Windows systems... The Zeppelin samples masquerade as legitimate Windows processes and seem to be linked to the PrintNightmare vulnerability exploitation.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The author of the publication describes the ransomware functionalities, including... scanning of all local drives and all available network paths
95 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
39 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in passing as a ransomware operation that has run an affiliate program.
Named ransomware family referenced as one of the third-party payloads used by Vice Society.
A third-party ransomware locker delivered in Vice Society attacks.
Zeppelin is identified as ransomware associated with the same shared IP infrastructure in February 2026.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.