Osiris
Osiris is ransomware first observed in November 2025.
Profile source: Ransomware.live opens in a new tabOsiris
Family profile
Osiris is ransomware first observed in November 2025. Reported intrusions used credential theft, remote-management tools, data exfiltration, and vulnerable-driver abuse before encryption. It is separate from the 2016 Locky variant and other malware also called Osiris.
Operational record
Reporting
Research mentioning Osiris
Ares - Technical Analysis | Zscaler Blog
The operator behind the Osiris banking trojan announced the malware's retirement after citing falling demand for banking malware, but security researchers report that the threat has not fully disappeared. Osiris, a descendant of Kronos, was sold to cybercrime groups and spread through spam campaigns to steal banking credentials, manipulate transactions on infected Windows systems, and exfiltrate data over Tor-based command-and-control infrastructure. Researchers also linked Osiris to rootkit features, theft of local application credentials, Outlook contact harvesting, spam-sending capability, TeamViewer deployment, and web injects aimed at German financial institutions. At the same time, a newer Kronos fork named Ares has emerged and appears to be developed by the same actor. Analysis shows Ares is modular and still evolving, with a stealer plugin, scheduled-task persistence, multiple hardcoded C2 URLs, and in-development VNC functionality, while custom packers such as DarkCrypter and BMPack are used to hinder analysis of both Ares and Osiris payloads. The Ares stealer can collect credentials, cookies, payment card data, cryptocurrency wallets, and files from browsers, VPN clients, email clients, and other applications, indicating the malware ecosystem is expanding rather than ending despite the claimed Osiris shutdown.