216.73.216.6

Osiris: New Ransomware, Experienced Attackers?

· Published 23/01/2026 10:08 · Modified 23/01/2026 10:33

Export JSON

Essential information

Published
23/01/2026 10:08
Modified
23/01/2026 10:33
Tags
2026-01-23 abyssworker byovd food service inc ransomware killav mimikatz osiris poortry ransomware rustdesk southeast asia wasabi
Related entities
17 observables, 1 intrusion sets (apt), 10 techniques (mitre), 6 malware, 3 others

Description

A new called was used in an attack on a major franchisee operator in in November 2025. The shares similarities with previous attacks, including the use of buckets for data exfiltration and a specific version of . has typical functions, uses a hybrid encryption scheme, and drops a ransom note. The attack chain involved data exfiltration using Rclone, deployment of dual-use tools, and the use of a malicious driver called or . The attackers employed bring-your-own-vulnerable-driver () techniques to disable security software. While the impact of on the landscape remains uncertain, it appears to be wielded by experienced attackers with potential links to or its affiliates.

External references