Obscura is a financially motivated ransomware operation that emerged in 2025 and operates a dedicated leak site to pressure alleged victims. The group has publicly claimed victims in healthcare, energy and utilities, industrial, professional-services, and media-related organizations. Available reporting identifies energy and utilities as a comparatively prominent focus among ransomware groups with meaningful victim volumes, although public leak-site listings should not alone be treated as confirmation of a full enterprise compromise or data theft. Obscura ransomware encrypts victim data, but an implementation defect reportedly makes files larger than 1 GB permanently unrecoverable even when a victim obtains a decryptor. Obscura operations have also been associated with bring-your-own-vulnerable-driver (BYOVD) tradecraft, a defense-evasion technique used to impair endpoint security controls before ransomware deployment. The operation is part of a broader ecosystem of small, short-lived ransomware crews rather than an established major ransomware-as-a-service brand.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation noted here for flawed encryption implementation causing irreversible file loss for large files.
Associated with healthcare-sector dedicated leak-site postings.
Referenced as a ransomware group observed using BYOVD-style defense evasion (vulnerable driver abuse) to impair endpoint defenses.
Ransomware group showing comparatively high focus on the energy and utilities industry.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.