Ransomware group
Obscura ransomware: victims and leak site activity
The Obscura ransomware group has listed 33 victims on its leak site since September 2025; its latest post is from 11 January 2026. Most affected countries: United States, Malaysia and Denmark. Most targeted sector: Professional Services.
Total posts
33
First seen
2025-09-05
Latest post
2026-01-11
Countries hit
14
About Obscura
Obscura is a ransomware strain observed in 2025, written in Go and specifically targeting Windows domain controllers via the SYSVOL/NETLOGON share, using Curve25519 + XChaCha20 encryption with double-extortion tactics and a 10-day payment deadline.
Most targeted countries
- United States 6
- Malaysia 5
- Denmark 3
- Thailand 3
- Egypt 2
- Ireland 2
- Portugal 2
- Canada 1
- Germany 1
- Greece 1
Most targeted sectors
- Professional Services 7
- Technology 6
- Energy & Utilities 4
- Healthcare 4
- Government & Defense 3
- Manufacturing 3
- Transportation 3
- Hospitality 1