Skip to content

obscura

Inactive

25 tracked victims · First seen Jul 16, 2025 · Last seen Jan 11, 2026

About

Aggregated threat-intel description

Obscura is a ransomware strain observed in 2025, written in Go and specifically targeting Windows domain controllers via the SYSVOL/NETLOGON share, using Curve25519 + XChaCha20 encryption with double-extortion tactics and a 10-day payment deadline.

Sectors: Healthcare, Technology, Transportation/Logistics · Countries: US, MY, DK

Recent victims

View all →
VictimSectorCountryPostedStatus
cle**rp**er.euNot FoundDec 15, 2025
k*m**w.comNot FoundDec 15, 2025
ACE ForwardingTransportation/LogisticsDec 12, 2025
Startek Engineering Inc.TechnologyTWDec 12, 2025
StanleyCo MalaysiaNot FoundMYDec 12, 2025
New Obscura 2.0!Not FoundDec 12, 2025
New Toyo International Holdings LtdManufacturingSGNov 1, 2025
Thompson Dorfman SweatmanBusiness ServicesCAOct 30, 2025
Federal Auto Holdings BerhadTransportation/LogisticsMYOct 29, 2025
Cape Dara Resort PattayaHospitality and TourismTHOct 20, 2025
relationmedia.dkTechnologyDKOct 13, 2025
meamargroup.comNot FoundEGOct 13, 2025
plazadental.comHealthcareUSOct 13, 2025
heavenly-dental.comHealthcareUSOct 13, 2025
thefixingcompany.comNot FoundIEOct 13, 2025
eastdesign.com.myNot FoundMYOct 13, 2025
espectral.ptTechnologyPTOct 13, 2025
michigancityin.govPublic SectorUSOct 13, 2025
EAST Design Architect Sdn. BhdConstructionMYSep 19, 2025
EspectralNot FoundPTSep 19, 2025
RelationMedia A/SNot FoundDKSep 5, 2025
Rulmaksan MakinaManufacturingTRSep 5, 2025
The Fixing CompanyNot FoundIESep 5, 2025
HeavenlyDentalHealthcareUSSep 5, 2025
PlazadentalHealthcareUSSep 5, 2025

All ransomware groups · Dark web intelligence