logo

Obscura, an obscure new ransomware variant

ID: a8d5405a-e8c3-565f-ac6d-d2a433668e15

STIX ID: report--a8d5405a-e8c3-565f-ac6d-d2a433668e15

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-09-24

Date Updated: 2026-07-17

Author: Sponsored by Huntress Labs

...
...

**Executive Summary:** Huntress Labs analyzes a newly observed ransomware variant named "Obscura" that was found on a domain controller and deployed via the NETLOGON/scripts share and scheduled tasks, encrypting files (full or partial) using X25519/XChaCha20 and appending a recoverable footer; the binary requires administrative privileges, terminates many security and backup processes, deletes volume shadow copies, and contains a base64-encoded ransom note claiming data theft and threatening leak unless paid. The report includes technical behavior, encryption and key-exchange details, exclusions list, observed IOCs (executable SHA256, ransom note filename, filesystem path, host name), and mitigation/monitoring guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.