Zeppelin was a ransomware operation active from 2019 until its disruption in 2022. It conducted financially motivated attacks against organizations and individuals in the United States and other countries, using file encryption, data theft, and extortion to pressure victims into paying. The operation has been associated with an affiliate-based ransomware model and with laundering ransom proceeds through cryptocurrency obfuscation and cash-out mechanisms. Public reporting and U.S. law-enforcement actions have linked Ianis Aleksandrovich Antropenko, a Russian national living in California, to a leadership role in the group. Zeppelin is widely tracked as a ransomware threat rather than a state-sponsored espionage actor. Its operations centered on post-compromise monetization through encryption and theft of victim data, consistent with double-extortion tradecraft. The group has also been named in reporting on cybercriminal financial infrastructure, including use of cryptocurrency mixing services to wash ransom payments. Known aliases in the provided material include Zeppelin and Zeppelin ransomware.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
70 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in passing as a ransomware operation that has run an affiliate program.
Ransomware operation; content references a leader pleading guilty and involvement in ransomware attacks prior to moving to the US.
Ransomware operations over multiple years (2018–2022 timeframe) targeting dozens of victims; leadership tied to a Russian national with cryptocurrency seizures linked to proceeds.
Referenced as a ransomware gang that used the Cryptomixer service to launder ransom payments.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.