BreachCensus

osiris

First seen December 18, 2025Active2 claimed victims

The claims below are reproduced as posted by osiris on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

Osiris is a ransomware-as-a-service operation first observed in November 2025 that uses a Bring Your Own Vulnerable Driver (BYOVD) technique to disable endpoint detection tools before deploying hybrid ECC + AES-128-CTR encryption; Symantec researchers linked its operators to former INC ransomware affiliates.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
American VanguardJanuary 9, 2026ransomware_live
The Araneta GroupDecember 10, 2025ransomware_live

Claim data from ransomware.live and RansomLook (CC BY 4.0).