Osiris

Inactive
Osiris is a ransomware-as-a-service operation first observed in November 2025 that uses a Bring Your Own Vulnerable Driver (BYOVD) technique to disable endpoint detection tools before deploying hybrid ECC + AES-128-CTR encryption; Symantec researchers linked its operators to former INC ransomware affiliates.
2 Victims
Dec 9, 2025 First Discovered
Jan 8, 2026 Last Discovered
251 Days Inactive
0% Infostealer
0/1 Sites Online
Known Locations (1)
Osiris
osirisbm3357xrccnid23nlyuqwzbgqheaei6dxvyi34tbkqr3bmvfid.onion
Victims (2)

Detailed victim list temporarily unavailable

This group has 2 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.