Obscura is a ransomware strain observed in 2025, written in Go and specifically targeting Windows domain controllers via the SYSVOL/NETLOGON share, using Curve25519 + XChaCha20 encryption with double-extortion tactics and a 10-day payment deadline. Known victims: 33 1 ransom note(s) on file
Objectives
Executive Summary
The Obscura ransomware strain, first seen in July 2025, targets Windows domain controllers via the SYSVOL/NETLOGON share, using Curve25519 + XChaCha20 encryption and double-extortion tactics. With a medium sophistication level and primary motivation of organizational gain, Obscura poses a significant threat to organizations. Its activities have been observed until at least January 2026, with 33 known victims.
Goals & Targeting
Obscura's strategic objectives appear to be focused on achieving financial gain through ransom payments, with a primary motivation of organizational gain. The targeting of Windows domain controllers suggests that the attackers are looking to maximize the impact of their attacks, and the use of double-extortion tactics further supports this goal. The typical victims of Obscura are likely to be organizations with sensitive data and critical systems, such as those in the finance, healthcare, and government sectors.
Enhanced Description
Given the relatively recent emergence of Obscura, it is likely that the attackers are continuing to develop and refine their tactics, techniques, and procedures (TTPs). As such, it is essential for organizations to remain vigilant and to implement robust security measures to prevent and detect Obscura ransomware attacks. This includes ensuring that Windows domain controllers are properly secured, implementing regular backups, and educating employees on the risks of ransomware and the importance of reporting suspicious activity.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Obscura's campaign patterns suggest a relatively slow and targeted approach, with a focus on exploiting Windows domain controllers and using double-extortion tactics to maximize the impact of their attacks. The attackers appear to be operating with a medium level of sophistication, and their activities have been observed over several months. Notable past operations include the compromise of 33 known victims, with the attackers likely seeking to expand their reach and increase their financial gains.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data is medium, as while there is some information on Obscura's TTPs and targets, there are still gaps in the understanding of the attackers' motivations and goals. Further research and analysis are necessary to fully understand the scope and impact of Obscura's activities.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
1
IOCs
0
Observed Data
0
Tactics