Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Osno registers the rootkit DLL to AppInit_DLLs and enables LoadAppInit_DLLs so it is loaded with every process... The rootkit uses MinHook to redirect WinAPI calls, so that it hides processes and file names
After execution of the Steam_Machine_Checker.exe, it opens the GUI screen of “Steam Machine Brute Force checker” in the frontend and starts its malicious activity in the backend.
the RunPE method and VM/Debugger/Sandbox detection code are taken from CSharp-RunPE
Instead it overwrites the original content of the files with a marker... Osno is a wiper in its current form and payment will not help to get any files back.
the RunPE method and VM/Debugger/Sandbox detection code are taken from CSharp-RunPE and Anti-Analysis by NYAN-x-CAT
Osno collects all accessible IP adresses in the local network
MSBuild.exe steals bookmarks, wallets, list of running process (using tasklist.exe), hardware and software installed – Anti-Virus, firewall etc.
MSBuild.exe steals bookmarks, wallets, list of running process (using tasklist.exe), hardware and software installed – Anti-Virus, firewall etc.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Osno is a rebranded Babax stealer that steals credentials and other data, adds persistence and stealth via the r77 rootkit, spreads laterally across local networks using SharpExec, weakens defenses by adding Windows Defender exclusions and targeting some AV processes, abuses Discord via AnarchyGrabber code, and includes a ransomware component that currently behaves as a wiper by overwriting files and appending the .osnoed extension.
A multifunctional malware family bundled in a fake Steam brute-force tool. It steals browser and wallet data, enumerates installed software and Wi‑Fi profiles, captures screenshots, exfiltrates data via Telegram Bot API, performs cryptocurrency clipboard hijacking by replacing Bitcoin addresses, and conducts coin mining on the victim host.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.