Osiris is a ransomware-as-a-service operation first observed in November 2025 that uses a Bring Your Own Vulnerable Driver (BYOVD) technique to disable endpoint detection tools before deploying hybrid ECC + AES-128-CTR encryption; Symantec researchers linked its operators to former INC ransomware affiliates. Known victims: 3
Objectives
Executive Summary
Osiris is a medium-sophistication ransomware-as-a-service operation that uses a Bring Your Own Vulnerable Driver technique to disable endpoint detection tools before deploying hybrid encryption. The group was first observed in November 2025 and has been linked to former INC ransomware affiliates. Osiris operators aim to achieve financial gain through ransomware attacks.
Goals & Targeting
Osiris targets organizations with the strategic objective of achieving financial gain through ransomware attacks. By using a ransomware-as-a-service model, the group seeks to maximize its returns by exploiting vulnerabilities across various sectors and geographies. The typical victims of Osiris are likely those who can afford to pay a ransom, suggesting that the group focuses on mid-to-large sized enterprises, potentially with less robust cybersecurity defenses or a higher willingness to pay ransoms to minimize downtime and protect sensitive data.
Enhanced Description
The Osiris operation has been observed targeting a variety of sectors and countries, although specific details on these targets are not publicly disclosed. Given the nature of ransomware-as-a-service models, it is plausible that Osiris operators cast a wide net, targeting any organization they believe can pay a substantial ransom. The use of BYOVD and hybrid encryption suggests a level of sophistication, though it is categorized as medium, indicating that while Osiris operators are adept at exploiting certain vulnerabilities, their overall capabilities may not be on par with more advanced threat actors.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Osiris has been active since November 2025, with a notable campaign pattern involving the use of its BYOVD technique to gain initial access to target networks. The operational tempo of Osiris suggests a consistent effort to identify and exploit potential victims, with an observed increase in activity through January 2026. Notable past operations include the compromise of at least three known victims, although the full scope of its campaigns is not publicly disclosed.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in the available data on Osiris is moderate, given the direct observation of its tactics, techniques, and procedures (TTPs) by security researchers. However, information gaps exist regarding the full scope of its operations, the exact sectors and countries targeted, and the potential for future evolution in its TTPs. Continuous monitoring and analysis of Osiris activities are necessary to fill these gaps and provide more comprehensive threat intelligence.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
1
Campaigns
0
IOCs
0
Observed Data
0
Tactics