Obscura

Inactive
Obscura is a ransomware strain observed in 2025, written in Go and specifically targeting Windows domain controllers via the SYSVOL/NETLOGON share, using Curve25519 + XChaCha20 encryption with double-extortion tactics and a 10-day payment deadline.
33 Victims
Jul 15, 2025 First Discovered
Jan 10, 2026 Last Discovered
249 Days Inactive
0% Infostealer
0/1 Sites Online
Known Locations (1)
Obscura Leaks Blog
obscurad3aphckihv7wptdxvdnl5emma6t3vikcf3c5oiiqndq6y6xad.onion
Intelligence
Victims (33)

Detailed victim list temporarily unavailable

This group has 33 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.