Skip to main content

Zeppelin Ransomware

First observed in November 2019, Zeppelin is an advanced ransomware-as-a-service tool based on the VegaLocker and Buran malware. Despite sharing large amounts of its code with these older tools, Zeppelin appears to be explicitly targeted at healthcare and technology organisations throughout Western Europe and the USA.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

First observed in November 2019, Zeppelin is an advanced ransomware-as-a-service tool based on the VegaLocker and Buran malware. Despite sharing large amounts of its code with these older tools, Zeppelin appears to be explicitly targeted at healthcare and technology organisations throughout Western Europe and the USA.


Affected platforms

The following platforms are known to be affected:

Threat details

At the time of publication, it is unclear how Zeppelin is delivered, although there are unconfirmed reports indicating it may be distributed via exposed Remote Desktop Services ports or though malvertising attacks in a similar manner to Buran.

Once delivered, Zeppelin will check the default language of the affected system and will terminate itself if Russian, Ukrainian, Kazakh, or Belarusian are detected. It then connects to a command and control server, which in turn sends an encryption command. Zeppelin will then attempt to terminate a number of database, recovery, and mail services before encrypting all reachable non-system files using an AES-256 algorithm in CBC mode. The AES keys are then themselves encrypted using a custom RSA-512 implementation.


Threat updates

Date Update
19 Dec 2019

Zeppelin has been delivered using the ConnectWise Control (formally Screen connect) remote management software on an already compromised network. The attack vector uses a variety of tools to disable Windows Defender and exfiltrate data before deploying Zeppelin as the final payload.


Remediation steps

Type Step

If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations.

To avoid becoming infected with ransomware, ensure that:

  • A robust program of education and awareness training is delivered to users to ensure they don’t open attachments or follow links within unsolicited emails.
  • All operating systems, anti-virus and other security products are kept up to date.
  • All day to day computer activities such as email and internet are performed using non-administrative accounts and that permissions are always assigned based on the principle of least privilege.
  • Your organisation adopts a holistic all-round approach to Cyber Security as advocated by the 10 Steps to Cyber Security.

Identifying the source of infection:
Identifying the affected device and disconnecting or quarantining it from the network is essential to damage limitation.

  • Users should immediately report infections to their IT support provider, disconnect their network cable and power the computer down.
  • File auditing should be enabled, and file server logs should be monitored to detect signs of unauthorised encryption and allow the source of encryption to be identified (i.e. the infected device).

To limit the damage of ransomware and enable recovery:
All critical data must be backed up, and these backups must be sufficiently protected/kept out of reach of ransomware.

  • Multiple backups should be created including at least one off-network backup (e.g. to tape).
    The only guaranteed way to recover from a ransomware infection is to restore all affected files from their most recent backup.

 

CFCBD89AC2A32EF179CB39ABB569A952
BFDFD9874072B6340660B501F1BD7A33
FEE6BA9A0D7A805B3281D4F955821C1C
A8E670C63E257049A7BCAE632C9ACEF6
0E06F623BC4EEFA97A84EDEDFBB6BB7E
3F120DE1249E8724EC1C1EF255F26067
0D442C4D8B4C4312840675CAC8D69661
58F53C8034A1E0AC1174595909DDF88C
386157F4CAB9327D01A7210DA9237EF0
357B149A0F40224DB5D359DB104A6778
68CCFAF0F453CC45FAAA8F653AB9C983
AED10704BFB8F9EFF057D5523B9AD431


Indicators of compromise

Main indicators

URLs

  • iplogger[.]org/1H7Yt7.jpg
  • iplogger[.]org/1HCne7.jpeg
  • iplogger[.]org/1Hpee7.jpeg
  • iplogger[.]org/1HVwe7.png
  • iplogger[.]org/1syG87
  • iplogger[.]org/1wF9i7.jpeg

Email Addresses

  • bad_sysadmin@protonmail[.]com
  • buratin@torbox3uiot6wchz[.]onion
  • buratino@firemail[.]cc
  • buratino2@tutanota[.]com
  • ran-unlock@protonmail[.]com
  • ranunlock@cock[.]li
  • Vsbb@firemail[.]cc
  • Vsbb@tutanota[.]com

Registry Keys

  • HKCU\Software\Zeppelin

SHA256 File Hashes

  • 04628e5ec57c983185091f02fb16dfdac0252b2d253ffc4cd8d79f3c79de2722
  • 1f94d1824783e8edac62942e13185ffd02edb129970ca04e0dd5b245dd3002bc
  • 39d8331b963751bbd5556ff71b0269db018ba1f425939c3e865b799cc770bfe4
  • 4894b1549a24e964403565c61faae5f8daf244c90b1fbbd5709ed1a8491d56bf
  • d61bd67b0150ad77ebfb19100dff890c48db680d089a96a28a630140b9868d86
  • e22b5062cb5b02987ac32941ebd71872578e9be2b8c6f8679c30e1a84764dba7

MD5

  • CFCBD89AC2A32EF179CB39ABB569A952
  • BFDFD9874072B6340660B501F1BD7A33
  • FEE6BA9A0D7A805B3281D4F955821C1C
  • A8E670C63E257049A7BCAE632C9ACEF6
  • 0E06F623BC4EEFA97A84EDEDFBB6BB7E
  • 3F120DE1249E8724EC1C1EF255F26067
  • 0D442C4D8B4C4312840675CAC8D69661
  • 58F53C8034A1E0AC1174595909DDF88C
  • 386157F4CAB9327D01A7210DA9237EF0
  • 357B149A0F40224DB5D359DB104A6778
  • 68CCFAF0F453CC45FAAA8F653AB9C983
  • AED10704BFB8F9EFF057D5523B9AD431

IP Addresses

  • 45.142.213[.]167
  • 216.249.104[.]215

Last edited: 29 June 2021 11:57 am