Osiris Ransomware Leverages POORTRY Driver in Novel BYOVD Attack
These articles are AI-generated summaries. Please check the original sources for full details.
New Osiris Ransomware Emerges as New Strain Using POORTRY Driver in BYOVD Attack
A new ransomware family, Osiris, was observed in a targeted attack against a food service franchisee in Southeast Asia in November 2025. This attack distinguished itself by employing a custom driver, POORTRY, within a Bring Your Own Vulnerable Driver (BYOVD) attack, effectively disabling security software.
Why This Matters
Current endpoint detection and response (EDR) solutions often rely on known signatures and behavioral patterns; however, BYOVD attacks bypass these defenses by leveraging trusted driver mechanisms. This allows attackers to disable security tools at a kernel level, rendering traditional protections ineffective and significantly increasing the potential scope of data compromise and financial loss – with ransomware incidents averaging $1.85 million in total cost in 2023 according to Sophos.
Key Insights
- BYOVD Attacks Increasing: The use of BYOVD techniques is on the rise, with Akira ransomware also exploiting vulnerable drivers in 2025.
- Rust-Based Malware: Osiris is written in Rust, indicating a trend towards memory-safe languages for malware development.
- INC Ransomware Link: Evidence suggests potential ties between the Osiris attackers and the INC ransomware group, based on shared tools and infrastructure.
Practical Applications
- Use Case: Food service companies are increasingly targeted due to valuable customer data and potential for operational disruption.
- Pitfall: Relying solely on signature-based detection is insufficient against advanced threats like Osiris, which utilize custom drivers and living-off-the-land techniques.
References:
Continue reading
Next article
Open Payment Standard x402 Expands Capabilities in Major Upgrade
Related Content
Reynolds Ransomware Embeds BYOVD Driver to Disable EDR Security Tools
Reynolds ransomware embeds a vulnerable BYOVD driver to kill EDR defenses, signaling advanced evasion in ransomware attacks with a 5.7 CVSS score.
Qilin Ransomware 'Korean Leaks' Campaign Compromises 28 South Korean Victims
Bitdefender attributes a large-scale data heist impacting 28 South Korean organizations to the Qilin ransomware group, resulting in 2TB of stolen data.
‘Sicarii’ Ransomware Decryption Fails Due to Poor Coding and Potential AI Use
The Sicarii ransomware strain exhibits a fatal flaw in its decryption process, rendering data irrecoverable even after ransom payment, due to key generation issues.