Zepto is a Windows ransomware strain that emerged in 2016 and is widely assessed as a Locky variant or direct evolutionary successor. It is closely associated with the same criminal ecosystem behind Locky and has been linked in industry reporting to large-scale malspam operations attributed to actors such as Evil Corp or TA505. Zepto encrypts victim files and appends a distinctive new extension, then presents ransom instructions through multiple artifacts including HTML and image-based notes and desktop wallpaper changes. Technical analysis has shown extensive code overlap with Locky, including highly similar encryption and file-selection logic, supporting the conclusion that Zepto is not a wholly separate family but a modified Locky lineage.
Zepto was prominently distributed through high-volume spam email campaigns using social-engineering lures themed around business communications. Delivery commonly involved compressed archives containing malicious JavaScript downloaders. When executed via the Windows Script Host, the downloader contacted command-and-control infrastructure over HTTP to retrieve the main ransomware payload. Some observed variants used multiple hardcoded servers for payload retrieval. After execution, the malware encrypted local files while avoiding certain system-critical targets, then displayed ransom demands to the victim.
Observed Zepto samples also incorporated defense-evasion features. Analysis identified anti-virtualization behavior based on timing checks, and some payloads altered execution in analysis environments by terminating their main thread and deleting themselves. Zepto’s operational model reflects the broader trend of downloader-based ransomware campaigns in which spam-delivered scripts fetch the final payload only after user execution.
Zepto primarily targeted Windows users and was observed at scale in indiscriminate email campaigns rather than narrowly focused sector-specific intrusions, although related Locky and Dridex delivery ecosystems have historically affected financial institutions and other organizations. Its significance lies both in its destructive file-encryption capability and in its role as a prominent example of the Locky ransomware ecosystem’s rapid iteration and reuse of established delivery infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The ransomware will scan the infected machine and encrypt data files such as text, image, and video files as well as office documents
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware delivered via spam emails with ZIP attachments containing a JavaScript downloader. The JS fetches the main payload from C2 servers, after which the malware encrypts files, appends the .zepto extension, and drops ransom note files including _HELP_instructions.jpg and _HELP_instructions.html. The sample discussed also used anti-VM timing checks via RDTSC.
Ransomware distributed via spam emails carrying ZIP archives with malicious JavaScript attachments. The JavaScript uses wscript.exe to issue HTTP GET requests to C2 domains, downloads and executes a binary, encrypts local files, appends the .zepto extension, and presents ransom instructions via dropped HTML/image files and wallpaper changes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.