The RIG Exploit Kit is Now Pushing the Buran Ransomware

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Forum Veteran
Feb 4, 2016
2,516
15,625
3,578
53
Germany / Poland
The RIG exploit kit is now infecting victim's computers with a new ransomware variant called Buran. This ransomware is a variant of the Vega ransomware that was previously being distributed through Russian malvertising campaigns.
First spotted by exploit kit researcher nao_sec, a malvertising campaign is redirecting users to the RIG exploit kit, which then drops the Buran ransomware as a payload.
 
After exploiting IE while browsing, it uses CMD and Windows Script Host scripting to download & install the ransomware.
214646
 

You may also like...