Friday, September 11, 2026

New Osiris Ransomware Leverages Living Off the Land and Dual-Use Tools in Attacks

A newly discovered ransomware family, Osiris, targeted a major foodservice franchisee in Southeast Asia in November 2025.

Despite sharing a name with a 2016 Locky ransomware variant, security researchers confirm this represents an entirely new threat with no connection to its predecessor.

However, evidence suggests potential links to threat actors previously associated with Inc ransomware operations.

The attackers employed extensive living off the land binaries (LOLBins) and dual-use tools throughout their campaign.

Notably, they leveraged the malicious Poortry driver in a bring-your-own-vulnerable-driver (BYOVD) attack to turn off security software on compromised systems.

The Symantec and Carbon Black Threat Hunter Team investigation revealed Osiris as a unique ransomware family with unknown developers and unclear operational structure.

Several tactical overlaps with the Inc ransomware operations emerged during the investigation. Attackers exfiltrated stolen data to Wasabi cloud storage buckets, a technique previously observed in Inc ransomware attacks from October 2025.

Additionally, the threat actors deployed Mimikatz using the identical filename “kaz.exe” that Inc ransomware operators previously used, suggesting either tactical emulation or direct involvement of former Inc affiliates.

Ransomware Technical Capabilities

Osiris exhibits standard ransomware functionality including service termination, selective folder and file extension encryption, process killing, and ransom note deployment.

The malware accepts multiple command-line parameters for customized operations: log file specification, file and directory path encryption targets, Hyper-V VM disabling with configuration deletion, VM-specific skipping, and encryption mode selection between partial (“head”) or complete (“full”) file encryption.

The ransomware strategically excludes specific file types from encryption including executables (.exe, .dll, .msi), media files (.mp4, .mp3, .mov, .avi), system files (.sys, .inf), and critical Windows directories such as Windows, PerfLogs, ProgramData, and System Volume Information.

Following encryption completion, Osiris appends the Osiris extension to affected files and deletes system snapshots using Volume Shadow Copy Service (VSS).

Osiris terminates database and productivity application processes including SQL, Oracle, MySQL, Microsoft Office applications (Excel, Word, Outlook, PowerPoint), communication tools (Firefox, Thunderbird), and system services.

The ransomware implements a hybrid encryption scheme combining Elliptic Curve Cryptography (ECC) with AES-128-CTR. Each encrypted file receives a unique AES key, while completionIOPort manages asynchronous input/output requests during encryption operations.

The malware also stops critical services like VSS, SQL services, Microsoft Exchange, and backup solutions including Veeam and GxVss.

Victims receive a ransom note titled “Osiris-MESSAGE.txt” containing stolen data claims and a negotiation chat link.

Attack Timeline and Tools

Initial suspicious activity appeared several days before ransomware deployment when attackers used Rclone to exfiltrate data to Wasabi cloud storage buckets.

The threat actors deployed multiple dual-use tools including Netscan for network reconnaissance, Netexec for lateral movement, and MeshAgent for remote access.

Notably, attackers used a customized Rustdesk remote monitoring and management tool, modified to masquerade as “WinZip Remote Desktop” complete with WinZip iconography to evade detection.

The attackers deployed the Abyssworker/Poortry malicious driver, disguised as a Malwarebytes anti-exploit driver, to execute a BYOVD attack for security software disablement.

Google’s Mandiant first documented Poortry in 2022, with subsequent usage in Medusa ransomware campaigns throughout 2024 and 2025. Poortry typically operates alongside the Stonestop loader, which installs the driver and directs its actions on victim machines.

BYOVD represents the most prevalent defense impairment technique among ransomware operators currently.

Attackers typically deploy signed vulnerable drivers that operate with kernel-mode access, enabling privilege escalation, security software termination, and process disruption.

Poortry differs from conventional BYOVD drivers as evidence suggests attackers developed it specifically for malicious purposes and successfully obtained legitimate code signing. Most BYOVD attacks exploit existing legitimate vulnerable drivers rather than custom-developed malicious drivers.

The attackers also deployed KillAV, a specialized tool for deploying vulnerable drivers to terminate security processes, and enabled Remote Desktop Protocol (RDP) for persistent remote access capability.

The full impact of Osiris ransomware on the broader threat landscape remains uncertain. However, the malware demonstrates effective encryption capabilities wielded by experienced operators.

Tactical overlaps with Inc ransomware operations particularly Wasabi cloud storage usage and identical Mimikatz deployment patterns indicate potential connections to that group or its affiliates.

Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth

Melbourne, Florida, September 10th, 2026, CyberNewswire With its Verification Architecture...

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

Nearly one in 10 internet-exposed LiteLLM AI gateways accepted...

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

Skullcandy Dime 3 wireless earbuds have a serious vulnerability...

Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly

Threat actors are increasingly exploiting Active Directory replication mechanisms...

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers

Threat actors are exploiting anticipation around Grand Theft Auto...

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O...

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

Palo Alto Networks has announced a high-severity buffer overflow...

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out...

Related Articles

Recent News