Hacking

New Osiris Ransomware Targets Food Service Operators in Southeast Asia

Published  ·  4 min read

The latest version of ransomware known as Osiris has been reported by Security research firm Crowdstrike after a Southeast Asia-based operator of multiple franchise food service businesses became a victim in November 2025. Unlike the previous variant developed and released by the creators of Locky (Osiris), the current variation was specifically developed for use as an entirely different family of ransomware. 

Therefore, to date, there is no known attribution for the codebase creator, and it is undetermined whether or not the Osiris variant operates as ransomware-as-a-service (RaaS). However, trends in the attack methods suggest possible ties to previously known attackers who were involved with INC ransomware (Warble).

Attack Techniques
The POORTRY method of attack utilized a malicious driver called POORTRY, which takes advantage of a technique called Bring Your Own Vulnerable Driver (BYOVD), which allows the attacker to disable security tools. 

POORTRY is unique in that it was created specifically for the purpose of privilege escalation and termination of security products. This is a significant distinction for many of the other examples of BYOVD attacks.

A few of the additional techniques observed in the attacks include:
1. The use of dual-use tools such as Netscan, Netexec, and MeshAgent.
2. The deployment of a custom Rustdesk remote desktop client.
3. Exfiltration of sensitive data using Rclone to the Wasabi Cloud Storage system
4. All-time access to RDP, allowing access to the target after the initial attack.
Both Symantec and Carbon Black have reported that the attackers also repurposed the Mimikatz (kaz.exe) technique used in the prior INC ransomware campaign.

Osiris Ransomware Features
Osiris Ransomware is the latest version of the Mimikatz ransomware. It is a difficult piece of software to use.
The following features are included in Osiris Ransomware:
1. Osiris uses different unique keys to encrypt each file individually, as well as hybrid encryption techniques.
2. It disables critical services on Microsoft Office, Exchange, Mozilla Firefox, Veeam, and more.
3. Ransomware operators have the ability to select the files that they wish to steal, stopping processes that were currently running, and providing additional instructions for victims via ransom notes.
4. The ability of Osiris to destroy files and its flexibility make it a very dangerous piece of malicious software for businesses.

Ransomware Threats of 2025
Criminals continue to use sophisticated methods for fraud and extortion:
1. Akira (Darter/Howling Scorpions) takes advantage of vulnerabilities in the driver programs and offers to deliver a Remote Access Trojan (RAT) using ClickFix CAPTCHA lures.
2. LockBit (Syrphid) maintained operations despite attempts by law enforcement agencies to shut it down, and the newly released version 5.0 features a two-step deployment process for evasion.
3. Sicarii is a Ransomware-as-a-Service (RaaS) group that is Israeli claimed; it primarily runs in the Russian-speaking underground but has limited victims.
4. Storm-2603 employs Velociraptor forensic drivers/tools while executing its ransomware as part of its BYOVD delivery mechanism.
5. Makop utilizes dual-use tools as a means of targeting exposed RDP services for reconnaissance and ability to conduct delivery.

Emerging Ransomware Threats
There is a developing trend of emerging ransomware products now available for use:
1. Obscura is designed to use an incorrect encryption pattern that results in losing large amounts of potentially recoverable data.
2. 01flip is written in Rust and targets Windows and Linux systems; it also exploits existing known security issues.
Symantec and Carbon Black have reported recording 4737 ransomware incidents in 2025, which is a slight increase from 4701 ransomware incidents in 2024.

Mitigating and Defending
There are several ways for organizations to help reduce risk. Among them are through: 
1. Monitoring and controlling the use of dual-use tools. 
2. Restricting the use of Remote Desktop Protocol (RDP) services. 
3. Utilizing Two-Factor Authentication (2FA) and 
4. Implementing Application Allowlisting.
5. Keeping Offline Backups at Off-site Locations. 

As Ransomware is only a small part of the overall Extortion Ecosystem, there are many ways that attackers are monetizing their attacks. Encrypting data without need to be discovered (i.e., no ransom demanded) is now becoming more popular, as are various methods of monetizing those attacks.

Source: The Hacker News

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067