Obscura, an Obscure New Ransomware Variant
ID: e949a1a2-d6e9-540a-87f0-acc7c1ff94e7
STIX ID: report--e949a1a2-d6e9-540a-87f0-acc7c1ff94e7
Feed Name: Huntress Blog
On 29 August 2025 Huntress analysts identified a previously unseen Go-based ransomware called “Obscura” that was placed in the domain controller NETLOGON/Sysvol scripts folder and thereby automatically replicated across the environment; the actor created scheduled tasks to execute the binary, enabled RDP via firewall changes, deleted volume shadow copies, and used aggressive process termination (targeting ~120 security/backup/database services) before encrypting files with XChaCha20/X25519 per-file keys. The report includes detailed technical analysis of privilege checks, daemon behavior, encryption/footer format, exclusion rules, and IOCs such as README_Obscura.txt and a provided SHA256 for the executable.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
