Osiris is a ransomware-as-a-service operation first observed in November 2025 that uses a Bring Your Own Vulnerable Driver (BYOVD) technique to disable endpoint detection tools before deploying hybrid ECC + AES-128-CTR encryption; Symantec researchers linked its operators to former INC ransomware affiliates.
What technical tactic does the Osiris ransomware group use to disable endpoint detection tools?+
Osiris uses the Bring Your Own Vulnerable Driver (BYOVD) technique to disable endpoint detection tools, loading a vulnerable kernel driver onto the target network.
Which former ransomware operators are linked to the Osiris ransomware-as-a-service group?+
Symantec researchers linked the Osiris group to former INC ransomware affiliates.