<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/new-osiris-ransomware-emerges-as-new-strain-using-poortry-driver-in-byovd-attack-ccvjdgfxq" -->

---
title: New Osiris Ransomware Emerges as New Strain Using...
description: Osiris is a new ransomware strain discovered in November 2025 that targeted a Southeast Asian food service operator using a BYOVD (Bring Your Own Vulnerable...
canonical: https://daily.dev/posts/new-osiris-ransomware-emerges-as-new-strain-using-poortry-driver-in-byovd-attack-ccvjdgfxq
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: New Osiris Ransomware Emerges as New Strain Using POORTRY Driver in BYOVD Attack | daily.dev
og:description: Osiris is a new ransomware strain discovered in November 2025 that targeted a Southeast Asian food service operator using a BYOVD (Bring Your Own Vulnerable...
og:url: https://daily.dev/posts/new-osiris-ransomware-emerges-as-new-strain-using-poortry-driver-in-byovd-attack-ccvjdgfxq
og:image: https://api.daily.dev/og/posts/CCVJdGFxq.png
og:image:alt: New Osiris Ransomware Emerges as New Strain Using POORTRY Driver in BYOVD Attack
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# New Osiris Ransomware Emerges as New Strain Using POORTRY Driver in BYOVD Attack

**[The Hacker News](https://daily.dev/sources/thn)** · 7 min read · 0 upvotes · 0 comments

## Summary

Osiris is a new ransomware strain discovered in November 2025 that targeted a Southeast Asian food service operator using a BYOVD (Bring Your Own Vulnerable Driver) attack with the POORTRY driver to disable security software. The ransomware uses hybrid encryption with unique keys per file and can terminate processes and services. Researchers found potential links to INC ransomware operators through shared tools and techniques. The attack involved data exfiltration to Wasabi cloud storage using Rclone, deployment of dual-use tools like Netscan and MeshAgent, and custom Rustdesk software. Ransomware attacks increased 0.8% in 2025 to 4,737 claimed incidents, with Akira, Qilin, and Play among the most active groups. The report also details recent developments including LockBit 5.0's two-stage deployment model, new RaaS operations like Sicarii, and various attack techniques exploiting RDP vulnerabilities.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://thehackernews.com/2026/01/new-osiris-ransomware-emerges-as-new.html>

## Similar posts on daily.dev

- [Black Basta Bundles BYOVD With Ransomware Payload](https://daily.dev/posts/black-basta-bundles-byovd-with-ransomware-payload-xkktwsdyu) · Dark Reading · 1 upvotes · 0 comments
- [How the GodDamn Ransomware Driver Bypasses Your EDR](https://daily.dev/posts/how-the-goddamn-ransomware-driver-bypasses-your-edr-6ruyzz7fu) · Latest Hacking News · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#cyber](https://daily.dev/tags/cyber), [#malware](https://daily.dev/tags/malware), [#ransomware](https://daily.dev/tags/ransomware)

[View this post on daily.dev](https://daily.dev/posts/new-osiris-ransomware-emerges-as-new-strain-using-poortry-driver-in-byovd-attack-ccvjdgfxq)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"New Osiris Ransomware Emerges as New Strain Using POORTRY Driver in BYOVD Attack","url":"https://daily.dev/posts/new-osiris-ransomware-emerges-as-new-strain-using-poortry-driver-in-byovd-attack-ccvjdgfxq","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/new-osiris-ransomware-emerges-as-new-strain-using-poortry-driver-in-byovd-attack-ccvjdgfxq"},"datePublished":"2026-01-22T19:12:00.313Z","dateModified":"2026-01-22T19:12:27.318Z","description":"Osiris is a new ransomware strain discovered in November 2025 that targeted a Southeast Asian food service operator using a BYOVD (Bring Your Own Vulnerable...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/d60122ac44cfac4c69e0931e8afa55d3?_a=AQAEulh","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/d60122ac44cfac4c69e0931e8afa55d3?_a=AQAEulh","isAccessibleForFree":true,"articleSection":"The Hacker News","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"The Hacker News","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/thn","url":"https://daily.dev/sources/thn"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/new-osiris-ransomware-emerges-as-new-strain-using-poortry-driver-in-byovd-attack-ccvjdgfxq","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,cyber,malware,ransomware","timeRequired":"PT7M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"The Hacker News","item":"https://daily.dev/sources/thn"},{"@type":"ListItem","position":3,"name":"New Osiris Ransomware Emerges as New Strain Using POORTRY Driver in BYOVD Attack"}]}
```

