Obscura, an obscure new ransomware variant
ID: a8d5405a-e8c3-565f-ac6d-d2a433668e15
STIX ID: report--a8d5405a-e8c3-565f-ac6d-d2a433668e15
Feed Name: Bleeping Computer
**Executive Summary:** Huntress Labs analyzes a newly observed ransomware variant named "Obscura" that was found on a domain controller and deployed via the NETLOGON/scripts share and scheduled tasks, encrypting files (full or partial) using X25519/XChaCha20 and appending a recoverable footer; the binary requires administrative privileges, terminates many security and backup processes, deletes volume shadow copies, and contains a base64-encoded ransom note claiming data theft and threatening leak unless paid. The report includes technical behavior, encryption and key-exchange details, exclusions list, observed IOCs (executable SHA256, ransom note filename, filesystem path, host name), and mitigation/monitoring guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
