Back to Ransomware Database
Ransomware Group
obscura
Obscura is a ransomware strain observed in 2025, written in Go and specifically targeting Windows domain controllers via the SYSVOL/NETLOGON share, using Curve25519 + XChaCha20 encryption with double-extortion tactics and a 10-day payment deadline.
Known victims33
Threat Level
MEDIUM
Check If You’re Affected
Search our database to see if your organization appears in obscura’s victim list.
Try it nowFree⌘K
Try
risk score · threat categories · sources · age · confidence — in one request