Zeppelin Ransomware
First observed in November 2019, Zeppelin is an advanced ransomware-as-a-service tool based on the VegaLocker and Buran malware. Despite sharing large amounts of its code with these older tools, Zeppelin appears to be explicitly targeted at healthcare and technology organisations throughout Western Europe and the USA.
Summary
First observed in November 2019, Zeppelin is an advanced ransomware-as-a-service tool based on the VegaLocker and Buran malware. Despite sharing large amounts of its code with these older tools, Zeppelin appears to be explicitly targeted at healthcare and technology organisations throughout Western Europe and the USA.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, it is unclear how Zeppelin is delivered, although there are unconfirmed reports indicating it may be distributed via exposed Remote Desktop Services ports or though malvertising attacks in a similar manner to Buran.
Once delivered, Zeppelin will check the default language of the affected system and will terminate itself if Russian, Ukrainian, Kazakh, or Belarusian are detected. It then connects to a command and control server, which in turn sends an encryption command. Zeppelin will then attempt to terminate a number of database, recovery, and mail services before encrypting all reachable non-system files using an AES-256 algorithm in CBC mode. The AES keys are then themselves encrypted using a custom RSA-512 implementation.
Threat updates
| Date | Update |
|---|---|
| 19 Dec 2019 |
Zeppelin has been delivered using the ConnectWise Control (formally Screen connect) remote management software on an already compromised network. The attack vector uses a variety of tools to disable Windows Defender and exfiltrate data before deploying Zeppelin as the final payload. |
Remediation steps
| Type | Step | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
|
Indicators of compromise
Last edited: 29 June 2021 11:57 am