New Osiris Ransomware Using Wide Range of Living off the Land and Dual-use Tools in Attacks
ID: 57d9b834-2ce6-5325-b250-caefe8e7f5bc
STIX ID: report--57d9b834-2ce6-5325-b250-caefe8e7f5bc
Feed Name: cybersecurityNews.com
A newly discovered ransomware family dubbed Osiris carried out a sophisticated November 2025 campaign against a major Southeast Asian food service company, combining credential theft (Mimikatz kaz.exe), data exfiltration via Rclone to Wasabi, deployment of a custom signed malicious driver (Poortry/Abyssworker) enabling BYOVD-style defense bypass, and a hybrid ECC+AES-128-CTR encryption routine that terminates databases, deletes snapshots, and hampers recovery — indicators point to experienced operators reusing tooling and advanced evasion tactics.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
