The VeganLocker malware strain provides the basis for a new ransomware, Buran, which attracts competitors through discounted prices.
According to McAfee researchers Alexandre Mundo and Marc Rivero Lopez, Buran was first detected in May 2019 and has now been added to other RaaS offerings, such as Revil and Phobos.

It was initially announced on a Russian forum, as Buran operators appear to be focused on establishing personal relationships with criminal clients.
In total, 25% of the illicit profits made through successful infections are taken by the authors, giving them a significant discount on the 30-40% typically required by RaaS operators.
The index can also be negotiated “with anyone who can guarantee an impressive level of contamination with Buran,” the researchers say.

Buran is described in the ad as a stable ransomware strain that uses offline cryptoclocker, 24/7 support, global and session.
The ransomware is also capable of scanning local drives and network paths and contains optional features, including file encryption.
Buran operators claim that the ransomware is compatible with all versions of the Microsoft Windows operating system, but McAfee found during its research that some older versions, including Windows XP, are not compatible.
The Rig exploit kit is the preferred delivery method for the new ransomware, and the Microsoft Internet Explorer VBScript Engine RCE vulnerability CVE-2018-8174 is used to exploit machines for deployment.

Two versions of Buran, written in Delphi, have been found so far – the second of which contains improvements over the original. The ransomware will check whether the victim's machine is registered in Russia, Belarus or Ukraine, and if these checks come back positive.
After ensuring that the ransomware program is able to create files and store them in temporary folders, Buran will create registry keys to maintain resilience, encrypt files, and post a ransom note.
Buran is derived from VegaLocker and Jumper and is considered to be the next stage of evolution due to similar behaviors, tactics, techniques, and procedures (TTPs) found in its code.
