The operator behind the Osiris banking trojan announced the malware's retirement after citing falling demand for banking malware, but security researchers report that the threat has not fully disappeared. Osiris, a descendant of Kronos, was sold to cybercrime groups and spread through spam campaigns to steal banking credentials, manipulate transactions on infected Windows systems, and exfiltrate data over Tor-based command-and-control infrastructure. Researchers also linked Osiris to rootkit features, theft of local application credentials, Outlook contact harvesting, spam-sending capability, TeamViewer deployment, and web injects aimed at German financial institutions.
At the same time, a newer Kronos fork named Ares has emerged and appears to be developed by the same actor. Analysis shows Ares is modular and still evolving, with a stealer plugin, scheduled-task persistence, multiple hardcoded C2 URLs, and in-development VNC functionality, while custom packers such as DarkCrypter and BMPack are used to hinder analysis of both Ares and Osiris payloads. The Ares stealer can collect credentials, cookies, payment card data, cryptocurrency wallets, and files from browsers, VPN clients, email clients, and other applications, indicating the malware ecosystem is expanding rather than ending despite the claimed Osiris shutdown.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
In March 2021, Anubi announced the shutdown of the Osiris banking trojan operation, citing declining interest in banking trojans on cybercriminal forums. Researchers noted, however, that some former customers might continue using Osiris in smaller operations.
Zscaler ThreatLabz identified a newer Kronos variant named Ares in February 2021 after it surfaced in spam campaigns targeting German speakers. The malware was assessed as an early-stage successor sharing similarities with Osiris.
The last major spam campaign distributing Osiris was observed in January 2021 and targeted German users. Reporting indicated Osiris activity had already been declining by that point.
A new Kronos variant named Osiris appeared in September 2018, introducing TOR for command-and-control communications. This marked the emergence of Osiris as a distinct successor in the Kronos malware lineage.
The Osiris banking trojan was originally advertised by its operator, Anubi, on a hacking forum in April 2018. It was presented as a revamped and improved version of Kronos.
Kronos first appeared in 2014 and was marketed on underground forums as a crimeware kit for credit card theft, identity theft, and wire fraud. Later Osiris and Ares variants were described as descendants of this malware family.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 52 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
blog.morphisec.com
Open sourcezscaler.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.