Zeppelin
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-06-17 14:49:49
- Profile updated
- 2026-07-07 13:04:59
Targeted industries: healthcare-and-pharmaceutical technology-and-telecommunications education-and-nonprofits financial-services
Context
Zeppelin is a strain of ransomware that encrypts the victim's files and demands a ransom for decryption. It primarily targets healthcare, technology, and educational sectors since its discovery in mid-2019.
Detection coverage
- 1 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Zeppelin (yara-rule)
Reports & references
- medium.com — Man1 Moskal Hancitor And A Side Of Ransomware D77B4D991618 (report)
- Microsoft — Dev 0832 Vice Society Opportunistic Ransomware Campaigns Impacting Us Education Sector (report)
- blackberry.com — Wp Spark State Of Ransomware (report)
- paloaltonetworks.com — Unit42 Ransomware Threat Report 2021 (report)
- ptsecurity.com — Paas Or How Hackers Evade Antivirus Software (report)
- Broadcom/Symantec — Sed Fy22Q2 Ses Ransomware Threat Landscape Wp (report)
- ransomlook.io — Zeppelin (report)
- blog.sekoia.io — Vice Society A Discreet But Steady Double Extortion Ransomware Group (report)
- CISA — Aa22 249A (report)
- community.riskiq.com — 47766Fbd (report)
- intrinsec.com — Vice Society Spreads Its Own Ransomware (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Zeppelin (report)
- storage.pardot.com — Flashpoint Hunt Team Zeppelin Ransomware Analysis (report)
- gdatasoftware.com — 35946 Burans Transformation Into Zeppelin (report)
- CISA — Aa22 223A (report)
- CISA — Aa22 223A Zeppelin Csa (report)
- threatvector.cylance.com — Zeppelin Russian Ransomware Targets High Profile Users In The Us And Europe (report)