Buran is a Windows ransomware family that emerged in 2019 and was operated as a ransomware-as-a-service offering on Russian-language underground forums. It is assessed as part of the VegaLocker and Jumper lineage and later served as a basis for the Zeppelin ransomware variant. Buran is a Delphi-based 32-bit encrypter that uses a packer and RunPE-style in-memory execution, encrypts files on local drives and accessible network shares, and drops a ransom note after encryption. Later versions added destructive recovery-inhibition features including deletion of shadow copies, backup catalogs, and system state backups.
The malware includes locale checks intended to avoid infecting systems associated with Russia, Belarus, and Ukraine. It establishes persistence on Windows by copying itself and creating autorun execution configured to survive Safe Mode. Buran also uses defense-evasion techniques such as packed execution, in-memory launching, and delayed execution behavior. It recursively enumerates network resources and encrypts data across logical drives and discovered shares, making it suitable for affiliate-led enterprise intrusions.
Observed delivery included exploitation through the Rig Exploit Kit using CVE-2018-8174. Buran has also appeared in broader criminal distribution ecosystems and has been observed as a payload delivered by other malware operations. The family is associated with financially motivated ransomware activity rather than a specific publicly attributed state actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Rig Exploit Kit was using CVE-2018-8174 (Microsoft Internet Explorer VBScript Engine, Arbitrary Code Execution) to exploit in the client-side. After successful exploitation this vulnerability will deliver Buran ransomware in the system. | McAfee’s Advanced Threat Research Team observed how a new ransomware family named ‘Buran’ appeared in May 2019. Buran works as a RaaS model like other ransomware families such as REVil, GandCrab (now defunct), Phobos, etc.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
If it is executed without any special argument, it will create a copy of Buran with the name “ctfmon.exe” in the Microsoft APPDATA folder
The goal of the packer is to decrypt the malware making a RunPE technique to run it from memory.
After that it will decrypt a registry subkey called “Software\Buran\Knock” in the HKEY_CURRENT_USER hive. For the mentioned key it will check the actual data of it
After this action the malware will enumerate all network shares with the functions : WNetOpenEnumA, WNetEnumResourceA WNetCloseEnum
In the analysis of Buran, we found how this ransomware blacklists certain files and folders.
The encryption process will start with special folders in the system like the Desktop folder. Buran can use threads to encrypt files
In the 2 nd version of Buran one of the main things added is the deletion of the shadow copies using WMI. Backup catalog deletion: Another feature added in the new version is the backup catalog deletion. ... we observed how Buran deletes in execution the system state backup in the system
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as the family lineage or predecessor related to Cuba.
Earlier malware family referenced as a basis for Zeppelin.
Buran is mentioned as ransomware downloaded onto systems already compromised by Danabot.
Ransomware family/variant referenced as potentially causing data corruption during encryption and providing buggy decryption tools leading to further data loss.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.