ZEPPELIN ransomware is a crypto virus that locks data with AES and then demands ransom in Bitcoin

ZEPPELIN ransomware is malware that renders all the files on the host machine completely useless, and then blackmails victims into paying a ransom in Bitcoin or another cryptocurrency. First spotted in late November 2019, it stems from the Buran ransomware family and functions very similarly to its previous versions.
Ransomware often infects its victims through phishing techniques, and they might not realize what happened until it's too late. The malware makes sure everything is clear to the victim post-infection by dropping a ransom note under readme.txt or !!! ALL YOUR FILES ARE ENCRYPTED !!! txt file name.
The message states that users cannot retrieve their files unless they contact hackers via zeppelindecrypt@420blaze.it, zeppelin_helper@tuta.io, or angry_war@protonmail.ch emails and pay the demanded ransom in Bitcoin.
Another sign of the virus infection is the appendix added to all the compromised files – it consists of nine randomly generated characters, for example, .126-A9A-0E9. While it is true that no Zeppelin ransomware decryptor is currently available, paying criminals is risky, as they might simply scam victims and never contact them again.
| Name | ZEPPELIN ransomware |
| Type | File locking malware, cryptovirus |
| Malware family | The virus is a version Buran ransomware family, which is a descendant of VegaLocker |
| Encryption algorithm | All files are locked with the help of sophisticated AES encryption algorithm – it uses symmetric keys to lock and unlock the data |
| File extension | Non-system files are appended with a randomly-generated marker that consists of nine characters (numbers and letters) |
| Ransom note | Users can find ransom note on the desktop of within the folders of affected files – readme.txt or !!! ALL YOUR FILES ARE ENCRYPTED !!!.txt |
| Contact | Emails zeppelindecrypt@420blaze.it, zeppelin_helper@tuta.io, or angry_war@protonmail.ch |
| Detection |
According to Virus Total, the ransomware is detected by various AV vendors under the following names:
|
| File decryption | There is a small chance of restoring encrypted files with file recovery software or by using Windows Previous Versions feature, although chances are low. The only secure and free way to recover data is by using backups, as paying ransom to cybercriminals does not guarantee positive results |
| Removal | To get rid of malware from the system, you should scan your computer with reputable anti-malware software, such as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes |
| Windows system fix | In case malware damaged certain system files that have a profound effect on the system's operation, we suggest scanning the machine with FortectIntego – it could fix all the virus damage and restore Windows registry |
Just like any other file locking malware, the ransomware executes various changes before performing the encryption process. For example, it creates various folders in the C drive and drops multiple files, opens and sets registry keys, deletes Shadow Volume Copies by using “vssadmin.exe Delete Shadows /All /Quiet” command, creates new and terminates processes, etc.
Due to these changes, the Windows system might start not to function as intended and start returning errors or crashing. In such a case, experts advise using FortectIntego to fix virus damage quickly. Additionally, for ZEPPELIN ransomware removal, victims should employ reputable anti-malware software and perform a full system scan in Safe Mode with Networking (not always required).
After all the preparations are complete, the virus starts the file encryption process. It targets most commonly-used file types, such as .pdf, .doc, .msi, .txt, .jpg, .dat, and others. The time of the encryption process depends on the size of the affected hard drive, as well as connected external devices and networks. After this, the malware also contacts its remote server where it retrieves the AES[1] key from. Each file encrypted in such a way is transformed – a blank icon is shown, and an additional extension is added. Thus, the infected users can expect to see a picture.jpg to be turned into picture.jpg.126-A9A-0E93.

After the data locking process, the ransomware drops a message which can be accessed via desktop or the encrypted files' folders. It states:
—=== Welcome. Again. ===—
[+] Whats Happen? [+]Your files are encrypted, and currently unavailable. You can check it: all files on your computer has extension 126-A9A-0E9
By the way, everything is possible to recover (restore), but you need to follow our instructions. Otherwise, you cant return your data (NEVER).[+] What guarantees? [+]
Its just a business. We absolutely do not care about you and your deals, except getting benefits. If we do not do our work and liabilities – nobody will not cooperate with us. Its not in our interests.To be sure we have the decryptor and it works you can send an email: zeppelindecrypt@420blaze.it and decrypt one file for free.
But this file should be of not valuable!
If you will not cooperate with our service – for us, its does not matter. But you will lose your time and data, cause just we have the private key. In practise – time is much more valuable than money.Write to email: zeppelindecrypt@420blaze.it
Reserved email: zeppelin_helper@tuta.io
Reserved jabber: zeppelin_decrypt@xmpp.jpYour personal ID: 126-A9A-0E9
!!! DANGER !!!
DONT try to change files by yourself, DONT use any third party software for restoring your data or antivirus solutions – its may entail damge of the private key and, as result, The Loss all data.
!!! !!! !!!
ONE MORE TIME: Its in your interests to get your files back. From our side, we (the best specialists) make everything for restoring, but please should not interfere.
!!! !!! !!!
It is a known tactic of cybercriminals to add an option of test decryption, as they are trying to establish a false sense of security. However, there are countless instances where victims of ransomware did not receive the decryption tool, even after paying the requested money.[2] Thus, rather remove the ransomware with anti-malware, and then use alternative recovery methods as provided below.
Note that hackers do not bluff when they say that the removal of malware could result in permanent data loss. To mitigate that, users should make a copy of locked files just in case.
Malware distribution methods vary – users should be more careful online
While many malware samples are quite difficult to get infected with, some advanced distribution methods might fool even those aware of online threats. Nevertheless, most of the ransomware infections occur with the help of some sort of social engineering or simple deception. Additionally, some users are aware of dangers but are still willing to risk malware infections – software cracks and pirated installers are one of the reasons why Djvu ransomware is so prominent nowadays. Therefore, users should not put themselves under unnecessary danger and never attempt to download cracking tools from torrent and similar sites in the first place.

There are several other security measures that users should pay close attention to, as explained by security experts from novirus.uk:[3]
- Install reputable security software capable of comprehensively protecting your machine in real-time;
- Apply all the Windows security patches without delaying them;
- Set all your installed software (especially such flawed components like Flash[4] or Java) to be updated automatically;
- Do not allow email attachments to execute a macro function, i.e., do not press “Allow content” once the MS Word or other document is opened; also, do not click on hyperlinks from unsolicited emails;
- Use strong passwords for all your accounts and apply two-factor authentication method where possible;
- Do not reuse your passwords;
- Turn of Remote Desktop connection when not used;
- Enable ad-blocking extensions;
- Turn off JavaScript autorun function.
Backup the encrypted data and then remove ZEPPELIN ransomware from your Windows machine
ZEPPELIN virus is ransomware, meaning that at its core, it is a complicated infection that is programmed to perform many different tasks once it infects the host. While some cryptoviruses self-delete, others lurk inside to encrypt all the new incoming files. In the latter case, ransomware removal is required prior to attempting data recovery. For that, victims should access Safe Mode with Networking and perform a full system scan to ensure that all the malicious components are eliminated. In case Windows struggles to function well after, the use of FortectIntego is recommended.
Note, before you remove the ransomware, it is just as equally important to make a backup of encrypted files on an external drive or a remote server. As already mentioned, the usage of anti-malware can damage the data and render it useless forever.
Options for data recovery include:
- Restoring from backups (safest and best way);
- Using third-party data recovery software (low chance of success);
- Paying cybercriminals for the decryptor (not recommended, as chances of being scammed remain).
Did this guide help?
Be the first to comment