Osiris is a Windows ransomware family first observed in November 2025 during a targeted intrusion against a major food-service franchisee in Southeast Asia. It is distinct from the older Locky-associated ransomware variant and the unrelated Kronos-derived banking trojan that share the Osiris name. Osiris supports selective, partial, or full encryption and uses hybrid ECC and AES-128-CTR cryptography with a unique AES key per encrypted file. It terminates database, backup, mail, productivity, and other processes that could lock files, deletes Volume Shadow Copies, avoids selected system content, and appends its own extension to encrypted files before presenting ransom demands. The associated operation exhibited double-extortion behavior, exfiltrating data with Rclone to cloud storage before encryption. Intrusion tooling included credential dumping, network-discovery and remote-management utilities, and a modified remote-access tool. Operators also used the Poortry/Abyssworker malicious driver in a BYOVD-style defense-evasion technique to disable endpoint security products. Tooling and tradecraft overlap with prior Inc ransomware activity, but attribution to Inc or a specific affiliate remains unconfirmed.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Phenakite comes bundled with the publicly available Osiris jailbreak and also includes the Sock Port exploit.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
According to an analysis by security firm Check Point, the trojan also employed advanced rootkits to get a permanent foothold inside infected hosts
After running the sample for the first time it adds itself to system startup and copies itself to %appdata%\Roaming\Microsoft\Windows\Protected\setspn.exe . Comparing the malicious setspn.exe with the Microsoft Original (which is normally found at C:\Windows\System32\setspn.exe) with the help of PEBear it is obvious that the files are not the same.
The first variant decrypts the next-stage payload using Blowfish... The second variant of the DarkCrypter packer embeds the second-stage payload in a compressed format... BMPack first decrypts embedded data using an XOR-based algorithm, followed by RC4.
It also has keylogging and hidden VNC functionality to help with its “banker” activities.
The trojan, which is a revamped and improved version of the Kronos malware (2014), is a classic banking trojan that infects Windows computers and then injects malicious code in web browsers to steal e-banking credentials and alter banking transactions.
The threat actor has an Osiris C2 server... instructing infected systems to steal and exfiltrate web browser and email credentials.
“Operators identify the most sensitive material, such as financial records, customer data, contracts, and source code.”
It also has keylogging and hidden VNC functionality to help with its “banker” activities.
Osiris introduced several new features including TOR for command and control (C2) communications... Most Ares samples currently do not communicate with C2 servers over TOR... Some Ares samples attempt to address this limitation by hardcoding a large number of C2 URLs in the binary.
In September 2018, a new Kronos variant named Osiris introduced several new features including TOR for command and control (C2) communications.
A quite interesting find: this Osiris sample uses a POC implementation called Mini-Tor for communication with the Tor network. Pretty convenient for the malware author as it keeps the size of the binary small, but still allows data exfiltration over an anonymized protocol.
53 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Double-extortion ransomware that exfiltrates data using Rclone, disables services and security software, deletes shadow copies, and encrypts victim systems.
Ransomware family that used a BYOVD technique leveraging the POORTRY driver to disable security software.
Ransomware family that uses a mix of legitimate Windows tooling and custom components to gain access, disable defenses, exfiltrate data, and encrypt systems for extortion.
Newly reported ransomware family (first spotted Nov 2025) using a hybrid encryption scheme (ECC + AES-128-CTR) with per-file keys, terminating processes (e.g., SQL/Oracle/Office apps) prior to encryption, and dropping a ransom note (Osiris-MESSAGE.txt) directing victims to a negotiation chat. Observed using living-off-the-land tooling and drivers to disable defenses and support extortion via data exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.