New Osiris Ransomware Leverages Living Off the Land and Dual-Use Tools in Attacks
ID: 51e6da26-2526-5040-ab09-f088bcfcdc8d
STIX ID: report--51e6da26-2526-5040-ab09-f088bcfcdc8d
Feed Name: GBHackers
A technical investigation outlines Osiris, a distinct ransomware family active in November 2025 that targeted a major foodservice franchisee in Southeast Asia. The report documents Osiris's hybrid ECC/AES-128-CTR encryption, selective file targeting and exclusion, VM and service disruption, use of multiple LOLBins and dual-use tools (Rclone, Netscan, Netexec, MeshAgent), and exfiltration to Wasabi cloud buckets. Operators employed a BYOVD attack using the Poortry/Abyssworker malicious driver (disguised as anti-exploit software) and used Mimikatz (kaz.exe) and a customized Rustdesk to facilitate credential theft and remote access; tactical overlaps with prior Inc ransomware operations suggest possible links or emulation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
