Osiris is an overloaded malware name that has been used for multiple unrelated threats. The best-supported and most substantial usage refers to a Windows banking trojan in the Kronos lineage. First advertised in 2018 as an improved descendant of Kronos, this Osiris variant targeted Windows systems and focused on financial fraud by injecting malicious code into web browsers, stealing online-banking credentials, and manipulating banking transactions. It communicated over Tor, including Mini-Tor-based implementations in some samples, and later updates added capabilities such as Outlook contact theft, spam-sending, TeamViewer deployment, remote-access features, and web injects aimed at German financial institutions. Reporting also attributes persistence and stealth features to the malware, including startup persistence and rootkit-style functionality, while associated tooling and later lineage developments indicate continued investment by the operator in packers, modular plugins, and credential-stealing components. Osiris has been linked to spam-driven distribution and was supplied to cybercrime groups for broad criminal use.
The name Osiris has also been used for other malware families. It was used for a Locky ransomware variant, but that usage refers to the Locky ecosystem rather than the Kronos-derived banking trojan. Separately, a distinct ransomware family named Osiris emerged in late 2025 and is not considered related to the earlier Locky variant; that ransomware used double-extortion tradecraft, Rclone-based exfiltration, and BYOVD-style defense evasion with the Poortry/Abyssworker driver to disable security tools before encrypting files with hybrid ECC and AES-128-CTR cryptography. In another unrelated context, “Osiris” also refers to a publicly available iOS jailbreak bundled by the Phenakite surveillance implant. Because these usages are unrelated, Osiris should be disambiguated carefully in operational and intelligence contexts. When used without qualification in malware-tracking contexts, it most often denotes the Kronos-derived banking trojan.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Phenakite comes bundled with the publicly available Osiris jailbreak and also includes the Sock Port exploit.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
According to an analysis by security firm Check Point, the trojan also employed advanced rootkits to get a permanent foothold inside infected hosts
After running the sample for the first time it adds itself to system startup and copies itself to %appdata%\Roaming\Microsoft\Windows\Protected\setspn.exe . Comparing the malicious setspn.exe with the Microsoft Original (which is normally found at C:\Windows\System32\setspn.exe) with the help of PEBear it is obvious that the files are not the same.
The first variant decrypts the next-stage payload using Blowfish... The second variant of the DarkCrypter packer embeds the second-stage payload in a compressed format... BMPack first decrypts embedded data using an XOR-based algorithm, followed by RC4.
It also has keylogging and hidden VNC functionality to help with its “banker” activities.
The trojan, which is a revamped and improved version of the Kronos malware (2014), is a classic banking trojan that infects Windows computers and then injects malicious code in web browsers to steal e-banking credentials and alter banking transactions.
The threat actor has an Osiris C2 server... instructing infected systems to steal and exfiltrate web browser and email credentials.
It also has keylogging and hidden VNC functionality to help with its “banker” activities.
Osiris introduced several new features including TOR for command and control (C2) communications... Most Ares samples currently do not communicate with C2 servers over TOR... Some Ares samples attempt to address this limitation by hardcoding a large number of C2 URLs in the binary.
In September 2018, a new Kronos variant named Osiris introduced several new features including TOR for command and control (C2) communications.
A quite interesting find: this Osiris sample uses a POC implementation called Mini-Tor for communication with the Tor network. Pretty convenient for the malware author as it keeps the size of the binary small, but still allows data exfiltration over an anonymized protocol.
53 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family that used a BYOVD technique leveraging the POORTRY driver to disable security software.
Ransomware family that uses a mix of legitimate Windows tooling and custom components to gain access, disable defenses, exfiltrate data, and encrypt systems for extortion.
Newly reported ransomware family (first spotted Nov 2025) using a hybrid encryption scheme (ECC + AES-128-CTR) with per-file keys, terminating processes (e.g., SQL/Oracle/Office apps) prior to encryption, and dropping a ransom note (Osiris-MESSAGE.txt) directing victims to a negotiation chat. Observed using living-off-the-land tooling and drivers to disable defenses and support extortion via data exfiltration.
Ransomware family referenced as newly observed; no additional technical details provided in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.