Researchers reported a large spam campaign distributing Zepto ransomware through ZIP archives containing malicious JavaScript files, often named with a swift theme. Cisco Talos observed 137,731 emails and 3,305 unique JavaScript samples over four days, with messages using executive-themed sender personas, customized salutations, and varied subject lines to lure recipients into opening the attachment. Once launched, the script used wscript.exe to contact hardcoded command-and-control domains over HTTP, download the payload, encrypt local files, append the .zepto extension, and present ransom demands through files including _HELP_instructions.jpg and _HELP_instructions.html, along with wallpaper changes.
Technical analysis found Zepto was not a wholly new family but an evolved Locky variant with extensive code overlap. Researchers said the malware reused Locky decoding behavior, including the 321 argument, and retained largely identical encryption and file-targeting logic, while adding features such as an RDTSC-based anti-VM check. Bindiff analysis showed a 0.86 similarity coefficient, with 99.9% of Locky’s 821 functions matched in Zepto, reinforcing that the campaign represented a significant continuation of spam-delivered Locky-style ransomware activity rather than a separate threat lineage.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
In July 2016, Zepto appeared as a new spam-delivered ransomware threat. Researchers reported that it encrypted files, added the .zepto extension, and dropped ransom note files named "_HELP_instructions.jpg" and "_HELP_instructions.html."
Cisco Talos said the Zepto ransomware email campaign began on Monday, 27 June, initially with about 4,000 emails observed in Cisco email security platforms. The campaign used ZIP archives containing JavaScript downloaders with the naming pattern "swift [XXX|XXXX].js."
Analysts found that the Zepto payload used an RDTSC-based anti-VM technique that caused it to kill its main thread and delete itself in the analysis environment. They patched the anti-VM instructions with NOPs, allowing the malware to run so the unpacked process could be dumped from memory after contacting domains for its RSA key.
Cisco Talos concluded that Zepto was either a new Locky variant or a ransomware family with extensive Locky copycat features. Technical analysis found the same payload decoding behavior using the argument "321" and largely identical encryption and file-targeting logic.
Over a four-day period ending with Talos's reporting, researchers identified 137,731 emails and 3,305 unique JavaScript samples distributing Zepto. Talos described the delivery chain in which the JavaScript used wscript.exe to fetch the payload from C2 domains, after which the ransomware encrypted files, appended the .zepto extension, and displayed ransom instructions.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.