The Zeppelin ransomware developers are continuing their activity after a period of relative silence that began last fall and have begun advertising new versions of the malware. A recent variant of the malware was made available on hacking forums in April, giving ransomware hackers complete independence.
Zeppelin ransomware , also referred to as "Buran," comes from the Vega/VegaLocker family, a ransomware-as-a-service (RaaS) that was spotted on Russian-language hacking forums in 2019.
The developers of the Zeppelin ransomware strain sell it on underground forums, giving buyers the ability to decide how they want to use the malware. They also have some individual collaboration with specific users of their malware.
Read also: DarkSide ransomware operation shut down – associates complain they haven't been paid

This contrasts with classic RaaS operations, where developers typically seek out partners to hack into a target's network, steal data, and develop file-encrypting malware. The two parties then split the profits made from ransom payments, with the developers taking the smaller share (up to 30%).
Advanced Intel (AdvIntel) found that the Zeppelin ransomware developers “revived” their activity in March. They announced “a major update to the software” along with a new round of sales. Following the major update, the Zeppelin developers released a new variant of the malware on April 27, which introduced a minor change in terms of features while also increasing the stability of the encryption.
They also assured regular customers that work on the malware was continuing and that long-term users, referred to as "subscribers," would benefit from special treatment.
Zeppelin is one of the few ransomware companies on the market that does not adopt the pure RaaS model, while it is one of the most popular gangs.
See also: Microsoft: Massive malware campaign distributes fake ransomware!

Yelisey Boguslavskiy, head of research at AdvIntel, explained how Zeppelin's developers operate, noting that they are working on "a more extensive scope of operations" with close partners who purchased the malware.
AdvIntel warns that despite the lack of organization typical of the RaaS model, Zeppelin could make it more difficult to combat the ransomware threat, as access to the malware allows other developers to steal features for their "products."
The company also says that Zeppelin users are individual buyers who do not complicate their attacks and rely on common initial attack vectors such as RDP, VPN vulnerabilities , and phishing .
Proposal: Six ransomware gangs have "hit" 292 organizations in 2021!

Additionally, Zeppelin operators do not have a data leak site, like most RaaS teams, while also focusing on data encryption rather than data theft.
AdvIntel recommends monitoring and controlling remote desktop and VPN connections as an effective defense against the Zeppelin ransomware threat.
Even without the sophistication of a RaaS operation, Zeppelin ransomware is a cause for concern, as attacks with this strain are difficult to detect, especially when new downloaders are used, as Juniper Threat Labs discovered last August.
Information source: bleepingcomputer.com
