Orca is a criminal ransomware group from the Zeppelin malware family targeting manufacturing and logistics sectors.
Analyst brief
Orca is a criminal ransomware group that emerged in September 2024 as a variant of the Zeppelin malware family. The group primarily targets organizations in the manufacturing and logistics sectors, with observed victims in Taiwan, Tunisia, Austria, and France, claiming to avoid hospitals, government institutions, and non-profits. Key TTPs include file encryption, likely double extortion tactics, and the use of a highly configurable ransomware payload characteristic of the Zeppelin lineage. Defenders should prioritize robust offline backups, strong email gateway filtering against phishing campaigns, and proactive monitoring for IOCs associated with Zeppelin ransomware variants.
orca
crime
Orca is a ransomware group that emerged in September 2024, identified as a variant of the Zeppelin malware family, targeting organizations in manufacturing and logistics across Taiwan, Tunisia, Austria, and France, claiming to avoid hospitals, government institutions, and non-profits.
What tactics does the Orca ransomware group use in its attacks?+
The Orca ransomware group uses key TTPs including file encryption and likely double extortion tactics, along with a highly configurable ransomware payload characteristic of the Zeppelin lineage.