Osiris ransomware emerges, leveraging BYOVD technique to kill security tools

Researchers identified a new Osiris ransomware used in a November 2025 attack, abusing the POORTRY driver via BYOVD to disable security tools.

Security Affairs

📰 New 'Osiris' Ransomware Borrows TTPs from Medusa and Inc Gangs, Uses Signed Driver to Kill AV

New Osiris ransomware borrows TTPs from Medusa & Inc gangs. 🐍 It uses a custom-signed driver ('Poortry') to kill EDR/AV before encrypting files. Also uses Rclone for data theft. #Ransomware #Osiris #BYOVD #ThreatIntel

🔗 https://cyber.netsecops.io/articles/new-osiris-ransomware-linked-to-medusa-and-inc-gang-ttps/?utm_source=mastodon&utm_medium=social&utm_campaign=twitter_auto

New 'Osiris' Ransomware Borrows TTPs from Medusa and Inc Gangs, Uses Signed Driver to Kill AV

The new Osiris ransomware strain shows links to Medusa and Inc groups, using a custom-signed malicious driver (Poortry/Abyssworker) to disable security software in a sophisticated BYOVD attack.

CyberNetSec.io
Jesus Resurrected Just Like Osiris!

YouTube
[OSIRIS] - Ransomware Victim: American Vanguard - RedPacket Security

NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating

RedPacket Security
New post from #Osiris : American Vanguard
More at : https://www.ransomlook.io/group/Osiris #Ransomware
osiris details

Open, searchable ransomware group intelligence with live stats, posts and an API.

Pyramids-Orion connection

YouTube
Giza Underground Structures, Richat and the Osirian Empire of Blavatsky

YouTube
OSIRIS Official Trailer (2025) Linda Hamilton

YouTube
[OSIRIS] - Ransomware Victim: The Araneta Group - RedPacket Security

NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating

RedPacket Security