logo

New Osiris Ransomware Using Wide Range of Living off the Land and Dual-use Tools in Attacks

ID: 57d9b834-2ce6-5325-b250-caefe8e7f5bc

STIX ID: report--57d9b834-2ce6-5325-b250-caefe8e7f5bc

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-01-22

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A newly discovered ransomware family dubbed Osiris carried out a sophisticated November 2025 campaign against a major Southeast Asian food service company, combining credential theft (Mimikatz kaz.exe), data exfiltration via Rclone to Wasabi, deployment of a custom signed malicious driver (Poortry/Abyssworker) enabling BYOVD-style defense bypass, and a hybrid ECC+AES-128-CTR encryption routine that terminates databases, deletes snapshots, and hampers recovery — indicators point to experienced operators reusing tooling and advanced evasion tactics.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.