Buran Ransomware
First observed in 2019, Buran (sometimes referred to as Vega but not related to the Vega browser spyware) is a ransomware tool targeting Europe and Central Asia.
Summary
First observed in 2019, Buran (sometimes referred to as Vega but not related to the Vega browser spyware) is a ransomware tool targeting Europe and Central Asia.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, Buran has only been observed being delivered by the RIG exploit kit via malvertising campaigns.
Once installed, Buran will attempt to encrypt all files not excluded using a hard-coded list, appending them with a unique identifier once done. Unlike most other ransomware, Buran will not attempt to delete Volume Shadow Copies or other backups.
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
|
Last edited: 14 February 2020 2:52 pm