Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors osiris

Description

Osiris is a ransomware-as-a-service operation first observed in November 2025 that uses a Bring Your Own Vulnerable Driver (BYOVD) technique to disable endpoint detection tools before deploying hybrid ECC + AES-128-CTR encryption; Symantec researchers linked its operators to former INC ransomware affiliates. Known victims: 3

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 2 weeks ago

Executive Summary

Osiris is a medium-sophistication ransomware-as-a-service operation that uses a Bring Your Own Vulnerable Driver technique to disable endpoint detection tools before deploying hybrid encryption. The group was first observed in November 2025 and has been linked to former INC ransomware affiliates. Osiris operators aim to achieve financial gain through ransomware attacks.

Goals & Targeting

Osiris targets organizations with the strategic objective of achieving financial gain through ransomware attacks. By using a ransomware-as-a-service model, the group seeks to maximize its returns by exploiting vulnerabilities across various sectors and geographies. The typical victims of Osiris are likely those who can afford to pay a ransom, suggesting that the group focuses on mid-to-large sized enterprises, potentially with less robust cybersecurity defenses or a higher willingness to pay ransoms to minimize downtime and protect sensitive data.

Enhanced Description

The Osiris operation has been observed targeting a variety of sectors and countries, although specific details on these targets are not publicly disclosed. Given the nature of ransomware-as-a-service models, it is plausible that Osiris operators cast a wide net, targeting any organization they believe can pay a substantial ransom. The use of BYOVD and hybrid encryption suggests a level of sophistication, though it is categorized as medium, indicating that while Osiris operators are adept at exploiting certain vulnerabilities, their overall capabilities may not be on par with more advanced threat actors.

Key Capabilities

  • Ransomware development and deployment
  • Use of Bring Your Own Vulnerable Driver (BYOVD) technique
  • Hybrid encryption (ECC + AES-128-CTR)
  • Endpoint detection evasion
  • Potential for customized attacks based on victim profile

MITRE ATT&CK Tactics

Defense Evasion
Credential Access
Discovery

ATT&CK Techniques

T1059.003
T1055
T1566.001

Software / Tooling

Custom ransomware
Vulnerable drivers for BYOVD

Campaigns & Victims

Osiris has been active since November 2025, with a notable campaign pattern involving the use of its BYOVD technique to gain initial access to target networks. The operational tempo of Osiris suggests a consistent effort to identify and exploit potential victims, with an observed increase in activity through January 2026. Notable past operations include the compromise of at least three known victims, although the full scope of its campaigns is not publicly disclosed.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting
  • Use of custom or commodity ransomware

Recommended Actions

  • Implement robust endpoint security controls
  • Regularly update and patch vulnerable software
  • Conduct thorough vulnerability assessments
  • Enhance employee cybersecurity awareness training
  • Consider implementing a ransomware incident response plan

Suggested Tags

Ransomware
Criminal
Medium Sophistication
Organizational Gain

Confidence Assessment

The confidence in the available data on Osiris is moderate, given the direct observation of its tactics, techniques, and procedures (TTPs) by security researchers. However, information gaps exist regarding the full scope of its operations, the exact sectors and countries targeted, and the potential for future evolution in its TTPs. Continuous monitoring and analysis of Osiris activities are necessary to fill these gaps and provide more comprehensive threat intelligence.

Intel Summary

0

Techniques

0

Tools

1

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Dec 10, 2025
Last Seen
Jan 18, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.