logo

Obscura, an Obscure New Ransomware Variant

ID: e949a1a2-d6e9-540a-87f0-acc7c1ff94e7

STIX ID: report--e949a1a2-d6e9-540a-87f0-acc7c1ff94e7

Feed Name: Huntress Blog

Threat Score
78/100

Date Published: 2025-09-02

Date Updated: 2026-04-28

...
...

On 29 August 2025 Huntress analysts identified a previously unseen Go-based ransomware called “Obscura” that was placed in the domain controller NETLOGON/Sysvol scripts folder and thereby automatically replicated across the environment; the actor created scheduled tasks to execute the binary, enabled RDP via firewall changes, deleted volume shadow copies, and used aggressive process termination (targeting ~120 security/backup/database services) before encrypting files with XChaCha20/X25519 per-file keys. The report includes detailed technical analysis of privilege checks, daemon behavior, encryption/footer format, exclusion rules, and IOCs such as README_Obscura.txt and a provided SHA256 for the executable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.