Osiris Banking Trojan
Osiris is a banking trojan that is a variant of Kronos. Osiris has been seen from April 2018.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Osiris is a banking trojan that is a variant of Kronos. Osiris has been seen from April 2018.
Affected platforms
The following platforms are known to be affected:
Threat details
Osiris can be spread by email campaign featured malicious documents containing macro-scripts and a new dropper that has been using process doppelgänging and process hollowing.
Osiris has the following Capabilities:
- Form grabber and Zeus-like web-injects compatible with the major browsers (Internet Explorer, Google Chrome, Mozilla Firefox, Microsoft Edge.)
- 32-bit and 64-bit rootkit.
- Antivirus and sandbox bypassing techniques.
- Encrypted communications with Command and Control (C2) server.
- Credit cards grabber.
- Keylogging
- TOR Proxy for communication with the C2
Threat updates
| Date | Update |
|---|---|
| 1 Apr 2021 |
New variant observed in spam campaign
Security researchers have observed a new variant of Osiris used alongside a new Kronos-based information stealer named Ares in a spam campaign targeting German speakers. Both are obfuscated by malware packers that have been called BMPack and DarkCrypter, which are not related to any commercial tools with the same name. The indicators of compromise in this article have been updated. |
Remediation advice
To prevent and detect a trojan infection, ensure that:Remediation steps
| Type | Step |
|---|---|
|
Indicators of compromise
Last edited: 1 April 2021 5:03 pm