osiris
First seen December 18, 2025Active2 claimed victims
The claims below are reproduced as posted by osiris on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
Osiris is a ransomware-as-a-service operation first observed in November 2025 that uses a Bring Your Own Vulnerable Driver (BYOVD) technique to disable endpoint detection tools before deploying hybrid ECC + AES-128-CTR encryption; Symantec researchers linked its operators to former INC ransomware affiliates.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| American Vanguard | January 9, 2026 | ransomware_live | — |
| The Araneta Group | December 10, 2025 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).