logo

New Osiris Ransomware Leverages Living Off the Land and Dual-Use Tools in Attacks

ID: 51e6da26-2526-5040-ab09-f088bcfcdc8d

STIX ID: report--51e6da26-2526-5040-ab09-f088bcfcdc8d

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-01-22

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A technical investigation outlines Osiris, a distinct ransomware family active in November 2025 that targeted a major foodservice franchisee in Southeast Asia. The report documents Osiris's hybrid ECC/AES-128-CTR encryption, selective file targeting and exclusion, VM and service disruption, use of multiple LOLBins and dual-use tools (Rclone, Netscan, Netexec, MeshAgent), and exfiltration to Wasabi cloud buckets. Operators employed a BYOVD attack using the Poortry/Abyssworker malicious driver (disguised as anti-exploit software) and used Mimikatz (kaz.exe) and a customized Rustdesk to facilitate credential theft and remote access; tactical overlaps with prior Inc ransomware operations suggest possible links or emulation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.