logo

Osiris ransomware emerges, leveraging BYOVD technique to kill security tools

ID: 261a1769-9c68-5c25-831b-2260a44e6718

STIX ID: report--261a1769-9c68-5c25-831b-2260a44e6718

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-01-24

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Symantec and VMware Carbon Black researchers uncovered a new Osiris ransomware strain used in a November 2025 attack against a major Southeast Asian food service operator that combined data theft (Rclone to Wasabi), privilege and credential theft (Mimikatz variant), and a BYOVD attack deploying the POORTRY driver to disable security products. The ransomware features hybrid ECC and AES-128-CTR per-file encryption, VSS deletion, targeted process/service termination, a .Osiris extension, and leaves an Osiris-MESSAGE.txt ransom note; attackers also used dual-use tools (Netscan, Netexec, MeshAgent) and a disguised RustDesk build, suggesting a skilled, organized operation with possible links to INC/Medusa affiliates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.