Osiris ransomware emerges, leveraging BYOVD technique to kill security tools
ID: 261a1769-9c68-5c25-831b-2260a44e6718
STIX ID: report--261a1769-9c68-5c25-831b-2260a44e6718
Feed Name: Security Affairs
Symantec and VMware Carbon Black researchers uncovered a new Osiris ransomware strain used in a November 2025 attack against a major Southeast Asian food service operator that combined data theft (Rclone to Wasabi), privilege and credential theft (Mimikatz variant), and a BYOVD attack deploying the POORTRY driver to disable security products. The ransomware features hybrid ECC and AES-128-CTR per-file encryption, VSS deletion, targeted process/service termination, a .Osiris extension, and leaves an Osiris-MESSAGE.txt ransom note; attackers also used dual-use tools (Netscan, Netexec, MeshAgent) and a disguised RustDesk build, suggesting a skilled, organized operation with possible links to INC/Medusa affiliates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
