Agencies advise action to protect against Zeppelin ransomware

The FBI and Cybersecurity and Infrastructure Security Agency yesterday urged organizations to take steps to protect against Zeppelin ransomware attacks, which use remote desktop protocol and firewall vulnerabilities and phishing campaigns to access victim networks and deploy ransomware.
鈥淭he Zeppelin 鈥楻ansomware as a Service鈥 is especially targeting health care and medical organizations,鈥 said John Riggi, AHA national advisor for cybersecurity and risk. 鈥淭he alert contains very detailed and actionable indicators of compromise which should be immediately loaded in organizations network defense systems. Along with encrypting files, this gang is engaging in the 鈥榙ouble layered鈥 data extortion method. It appears this gang is stealing and threatening to publicly release sensitive information such as patient information, payroll, human resources and non-disclosure-protected information. Thus, even if a victim organization can independently restore encrypted files from backup, they face the dilemma of potential public release of stolen information in the possession of the criminals. The AHA, along with the federal government, strongly discourages the payment of ransom. This alert along with the comprehensive provide extensive guidance on how to protect your systems from ransomware and avoid the ethical and legal dilemma of 鈥榩ay, not pay.鈥欌
For more information on this or other cyber and risk issues, contact Riggi at jriggi@aha.org.