VegaLocker
Aliases: Buran, Vega
- First seen
- 2019-01-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-18 01:17:20
- Profile updated
- 2026-07-07 13:05:01
Targeted industries: financial-services healthcare-and-pharmaceutical education-and-nonprofits technology-and-telecommunications
Context
VegaLocker, also known as Buran, is a ransomware family that encrypts files on infected systems and demands a ransom for decryption. It has been active since early 2019 and primarily targets various industries worldwide.
Detection coverage
- 3 YARA rules
Detection rules
- TRELLIX_ARC_Buran_Ransomware (yara-rule)
- ARKBIRD_SOLG_Ran_Buran_Oct_2020_1 (yara-rule)
- DITEKSHEN_MALWARE_Win_Buran (yara-rule)
Reports & references
- medium.com — Man1 Moskal Hancitor And A Side Of Ransomware D77B4D991618 (report)
- Broadcom/Symantec — Sed Fy22Q2 Ses Ransomware Threat Landscape Wp (report)
- ransomlook.io — Vegalocker (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Vegalocker (report)
- McAfee — Buran Ransomware The Evolution Of Vegalocker (report)
- twitter.com — 1095024267459284992 (report)
- twitter.com — 1093136163836174339 (report)