Executive SummaryRisk level: High
What happened

Osiris ransomware uses Bring Your Own Vulnerable Driver (BYOVD) techniques – abusing a vulnerable signed driver (POORTRY) – to disable security tooling and execute with elevated privileges before encrypting data; a major Southeast Asian food-service franchise was hit in November 2025.

Who is affected

Windows environments whose EDR/AV can be neutralized via vulnerable drivers; the named victim is a major Southeast Asian food-service franchise.

Why it matters

BYOVD lets ransomware operate beneath endpoint defenses, escalate privileges, and encrypt at scale, threatening operational continuity and data confidentiality.

Immediate recommended actions

  • Enable Microsoft's vulnerable-driver blocklist with WDAC and HVCI.
  • Alert on 'sc stop' and other service-stop commands targeting security tools.
  • Hunt for loads of known-vulnerable drivers (Sysmon EID 6).
  • Maintain offline, tested backups and segment critical systems.
How to read this report. Items are labelled by confidence: Confirmed stated as fact in the source, Reported described by the source, Potential analyst inference, and Requires Validation to be confirmed in your environment. Where the source lacks detail this is stated as “Not specified in the source material”.

Key Technical Findings

Vulnerability / Campaign Type

Ransomware leveraging BYOVD for defense evasion and privilege escalation.

Affected Systems

Windows endpoints and servers that permit loading of vulnerable drivers; victim in the Southeast Asian food-service sector.

Initial Access Vector

Phishing emails or exploit kits delivering the initial payload.

Execution Method

Exploitation for client execution (T1203) using a vulnerable driver (POORTRY).

Persistence

Modified system configuration and scheduled tasks to survive reboot.

Privilege Escalation

Exploitation of the vulnerable driver to gain elevated privileges (T1068).

Defense Evasion

Loading a legitimate-but-vulnerable driver and using 'sc stop' to disable security software.

Credential Access

Credential harvesting from memory or keylogging (Potential – requires validation).

Lateral Movement

Use of harvested credentials to spread across the network.

Data Exfiltration

Data aggregated and exfiltrated prior to encryption (double extortion).

Impact Level

High – file encryption, ransom demands, and operational disruption.

Technical Background

BYOVD abuses a legitimately signed but vulnerable kernel driver to gain kernel-level capabilities, which attackers use to terminate or blind endpoint security products that user-mode malware could not touch. Osiris reportedly leverages the POORTRY driver to execute with elevated privileges while evading detection.

The operators issue commands such as sc stop to disable security services, then proceed through privilege escalation, discovery, lateral movement, and encryption. The technique underscores the need for driver allow/block-listing and kernel-integrity controls, since traditional endpoint monitoring can be neutralized.

Attack Chain Analysis

  1. Initial Access

    ActivityDelivery via phishing emails or exploit kits.

    EvidenceSuspicious inbound mail and first-seen payload execution.

    TelemetryEmail gateway, EDR, Sysmon EID 1.

    Detection opportunityCorrelate lure delivery with subsequent execution.

  2. Execution

    ActivityLoad and exploit the vulnerable POORTRY driver (T1203).

    EvidenceLoad of a known-vulnerable driver.

    TelemetrySysmon EID 6 (driver load), EDR.

    Detection opportunityAlert on vulnerable-driver loads against the Microsoft blocklist.

  3. Privilege Escalation

    ActivityAbuse the driver vulnerability for elevated privileges (T1068).

    EvidenceKernel-level actions from an unexpected process.

    TelemetryEDR kernel telemetry.

    Detection opportunityDetect user-mode processes obtaining kernel capabilities.

  4. Defense Evasion

    ActivityDisable security software via 'sc stop' and driver abuse.

    EvidenceSecurity services stopped or tampered.

    TelemetryService control (7036/7045), EDR tamper alerts.

    Detection opportunityAlert on stop commands against AV/EDR services.

  5. Persistence

    ActivityModify configuration and add scheduled tasks.

    EvidenceNew tasks/services configured to run at boot.

    TelemetrySecurity 4698/7045, Sysmon.

    Detection opportunityHunt for new persistence created during the intrusion.

  6. Lateral Movement

    ActivitySpread using harvested credentials.

    EvidenceUnexpected remote logons across hosts.

    TelemetrySecurity 4624/4648.

    Detection opportunityFlag off-baseline remote authentications.

  7. Exfiltration

    ActivityAggregate and exfiltrate data before encryption.

    EvidenceEgress volume anomalies prior to mass encryption.

    TelemetryProxy/firewall, DLP.

    Detection opportunityDetect staging and large outbound transfers.

  8. Impact

    ActivityEncrypt files and present ransom notes (T1486).

    EvidenceHigh-rate file modification/rename and ransom notes.

    TelemetryEDR/FIM, file-audit logs.

    Detection opportunityAlert on rapid mass file changes to uncommon extensions.

Deep Technical Behavior Analysis

The defining behavior is kernel-level defense evasion: by loading a vulnerable signed driver, Osiris obtains capabilities sufficient to terminate endpoint protection before encryption. The observed sc stop usage is a practical, high-signal indicator that security services are being disabled mid-intrusion.

Credential harvesting (memory access or keylogging) is described as a capability but should be treated as Potential – requires validation. Exact driver hashes, ransom-note filenames, and encryption parameters are not specified in the source material.

Indicators of Compromise

No indicators of compromise were provided in the source material.

Indicators of Behavior

Behavioral indicators to hunt for even when atomic IoCs are limited (Potential — validate against your baseline).

Behavioral Indicator Description Data Source Confidence
Anomalous PowerShell execution Encoded/obfuscated commands, download cradles, or unusual parent-child process lineage. Sysmon EID 1, PowerShell 4104 Potential
Suspicious child process lineage Office or web/service processes spawning script hosts or shells. Sysmon EID 1, EDR Potential
Security log clearing Event log cleared or audit policy changed to hinder visibility. Windows Security 1102, 4719 Potential
New service / scheduled task creation Unexpected persistence via services or tasks. Security 7045, 4698; Sysmon Potential
Beaconing to rare destinations Periodic outbound connections to newly-seen domains/IPs or direct-IP C2. Proxy, firewall, DNS logs Potential
Unusual DNS queries High-entropy or rare domains; possible tunneling. DNS resolver logs Potential
Authentication anomalies Spraying/stuffing, impossible travel, or MFA fatigue patterns. IdP/VPN logs, Azure AD/Okta sign-ins Potential

Detection Engineering Guidance

Defensive detection logic (Potential — tune to your environment). No exploit code is included; logic is for hunting and alerting only.

Baseline detection guidance
  • ObjectiveSurface anomalous process, persistence, and outbound activity.
  • Data sourceEDR, Sysmon, authentication and proxy/DNS logs.
  • ResponseTriage, validate, preserve evidence, contain if confirmed.
Platform Log Source What to Look For Priority
Windows Security Event Log Logon (4624/4625), service (7045), task (4698), log clear (1102) High
Windows Sysmon Process creation (1), network (3), image load (7), LSASS access (10) High
Windows PowerShell Operational Script block logging (4104), module logging High
Endpoint EDR / Defender telemetry Process tree, persistence, tamper attempts High
Identity IdP / VPN logs Impossible travel, spraying, MFA fatigue High
Network DNS resolver logs Rare/high-entropy domains, tunneling Medium
Network Proxy / firewall logs Beaconing, direct-IP C2, exfil volume High

MITRE ATT&CK Mapping

Tactic Technique ID Technique Name Relevance Detection Opportunity Confidence
Execution T1203 Exploitation for Client Execution Exploits vulnerabilities to execute malicious payloads. Review logs for unusual application behavior during execution times. Reported
Privilege Escalation T1068 Exploitation of Elevation of Privilege Takes advantage of vulnerabilities in system components to gain elevated privileges. Monitor for unauthorized access attempts or unusual process activity. Reported

Incident Response Guidance

  • Validate exposure and confirm whether the issue applies to your environment.
  • Preserve evidence (memory, disk, relevant logs) before remediation.
  • Isolate affected hosts/accounts if compromise is suspected.
  • Collect volatile data and review the log sources listed above.
  • Hunt for the indicators of behavior and any related atomic indicators.
  • Rotate potentially exposed credentials, keys, and session tokens.
  • Remove persistence (tasks, services, keys, web shells, cron, OAuth grants).
  • Patch affected systems; reimage where integrity cannot be assured.
  • Run post-remediation validation and a BAS/security-validation retest.

Remediation and Hardening

  • Patch affected systems and reduce internet-exposed services.
  • Enforce MFA and least-privilege for privileged and remote access.
  • Improve endpoint telemetry (Sysmon/EDR) and PowerShell logging.
  • Restrict script execution and constrain LOLBins where feasible.
  • Monitor persistence locations and disable unnecessary services.
  • Segment critical assets and review privileged accounts.
  • Rotate secrets and remove credentials from configuration files.
  • Tune SIEM/EDR detections, then validate controls after changes.

Business Risk

  • Service disruption: degraded or unavailable systems during compromise or recovery.
  • Data exposure: risk to sensitive, regulated, or customer data depending on scope.
  • Regulatory exposure: potential breach-notification and compliance obligations.
  • Financial impact: incident response, downtime, and potential extortion costs.
  • Brand and trust impact: reputational damage with customers and partners.
  • Operational continuity: ransomware can halt critical business processes until restored.
  • Identity blast radius: compromised accounts can expand access across cloud and SaaS.

Executive Takeaway

What leadership needs to know: BYOVD lets ransomware operate beneath endpoint defenses, escalate privileges, and encrypt at scale, threatening operational continuity and data confidentiality. Current assessed risk: High.

Prioritise: patching/exposure reduction, identity hardening (MFA, least privilege), and detection coverage for the techniques above.

Validate after remediation: re-test controls with breach & attack simulation to confirm the relevant techniques are now prevented or detected.

Validating Your Defenses with Valitrix

The Valitrix Breach and Attack Simulation (BAS) platform allows organizations to emulate specific MITRE ATT&CK techniques, including those used by Osiris ransomware. By simulating these attacks in a controlled environment, security teams can verify that their detection mechanisms are effective against real-world threats. This proactive approach helps identify gaps in defenses before they can be exploited by actual attackers.

This continuous validation not only enhances an organization’s resilience against ransomware but also reinforces confidence in their incident response capabilities. With Valitrix, organizations can ensure that their security posture is not just theoretical but validated against evolving threats like Osiris ransomware.

Key Takeaways

  • The Osiris ransomware leverages BYOVD techniques to exploit driver vulnerabilities and bypass security measures.
  • A comprehensive understanding of the attack chain is essential for effective defense strategies.
  • Regular updates and robust endpoint protection are critical in mitigating ransomware risks.
  • The Valitrix BAS platform enables organizations to validate their defenses against real-world attack scenarios.

Frequently Asked Questions

What is BYOVD in relation to ransomware?

BYOVD stands for Bring Your Own Vulnerable Driver, a technique where attackers exploit existing vulnerable drivers on a victim’s system to execute malicious payloads with elevated privileges.