The Hacker News
Read post

New Osiris Ransomware Emerges as New Strain Using POORTRY Driver in BYOVD Attack

Osiris is a new ransomware strain discovered in November 2025 that targeted a Southeast Asian food service operator using a BYOVD (Bring Your Own Vulnerable Driver) attack with the POORTRY driver to disable security software. The ransomware uses hybrid encryption with unique keys per file and can terminate processes and services. Researchers found potential links to INC ransomware operators through shared tools and techniques. The attack involved data exfiltration to Wasabi cloud storage using Rclone, deployment of dual-use tools like Netscan and MeshAgent, and custom Rustdesk software. Ransomware attacks increased 0.8% in 2025 to 4,737 claimed incidents, with Akira, Qilin, and Play among the most active groups. The report also details recent developments including LockBit 5.0's two-stage deployment model, new RaaS operations like Sicarii, and various attack techniques exploiting RDP vulnerabilities.

    #security#cyber#malware#ransomware
Jan 22•7m read time•From thehackernews.com
Post cover image
176 Impressions
The Hacker News's image
The Hacker News

The Tidyverse Blog offers insights, tutorials, and updates on the Tidyverse, a collection of R packa...

2.3K Followers

•

1.7K Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard