Zeppelin

Malware type
ransomware
Family
Malware family
Last IoC activity
2026-06-17 14:49:49
Profile updated
2026-07-07 13:04:59

Targeted industries: healthcare-and-pharmaceutical technology-and-telecommunications education-and-nonprofits financial-services

Context

Zeppelin is a strain of ransomware that encrypts the victim's files and demands a ransom for decryption. It primarily targets healthcare, technology, and educational sectors since its discovery in mid-2019.

Detection coverage

  • 1 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Zeppelin (yara-rule)

Reports & references

  • medium.com — Man1 Moskal Hancitor And A Side Of Ransomware D77B4D991618 (report)
  • Microsoft — Dev 0832 Vice Society Opportunistic Ransomware Campaigns Impacting Us Education Sector (report)
  • blackberry.com — Wp Spark State Of Ransomware (report)
  • paloaltonetworks.com — Unit42 Ransomware Threat Report 2021 (report)
  • ptsecurity.com — Paas Or How Hackers Evade Antivirus Software (report)
  • Broadcom/Symantec — Sed Fy22Q2 Ses Ransomware Threat Landscape Wp (report)
  • ransomlook.io — Zeppelin (report)
  • blog.sekoia.io — Vice Society A Discreet But Steady Double Extortion Ransomware Group (report)
  • CISA — Aa22 249A (report)
  • community.riskiq.com — 47766Fbd (report)
  • intrinsec.com — Vice Society Spreads Its Own Ransomware (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Zeppelin (report)
  • storage.pardot.com — Flashpoint Hunt Team Zeppelin Ransomware Analysis (report)
  • gdatasoftware.com — 35946 Burans Transformation Into Zeppelin (report)
  • CISA — Aa22 223A (report)
  • CISA — Aa22 223A Zeppelin Csa (report)
  • threatvector.cylance.com — Zeppelin Russian Ransomware Targets High Profile Users In The Us And Europe (report)

External references