Skip to content
skopnix
← adversaries
Crime

obscura

ransomware.liverefreshed 2026-09-15

sigil

Analyst brief

Obscura is a ransomware strain observed in 2025, written in Go and specifically targeting Windows domain controllers via the SYSVOL/NETLOGON share, using Curve25519 + XChaCha20 encryption with double-extortion tactics and a 10-day payment deadline.

Take it with you
References
Early access

Track obscura on the wire.

Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.

bot-protected