Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareRansomware

Obscura

Obscura, also referred to as Obscura Locker, is a ransomware family first observed in late August to early September 2025. It encrypts victim files using AES and RSA and appends the .obscura extension. The ransom note is named README-OBSCURA.txt and states that the victim network has been encrypted and that data from devices across the network, including NAS systems, has been stolen, indicating double-extortion behavior. The note threatens publication of stolen data if the victim does not respond within about 240 hours and provides victim contact details via a TOX ID beginning with AE55FC0EB1C25A5B081650108F9081E23 and the Tor site obscurad3aphckihv7wptdxvdnl5emma6t3vikcf3c5oiiqndq6y6xad.onion. Reported delivery vectors include exposed or insecure RDP, phishing or spam emails with malicious attachments, exploit-based delivery, deceptive downloads, malvertising, fake updates, botnets, web injects, and trojanized installers. Technically, Obscura deletes shadow copies using "cmd.exe /c vssadmin delete shadows /all /quiet", terminates processes that may interfere with encryption, and excludes various system, boot, firmware, configuration, and already-encrypted file types from encryption. The malware has been reported to use a BYOVD (Bring Your Own Vulnerable Driver) technique to evade or bypass security protections, and separate reporting cites an Obscura incident in late August 2025 as an example of ransomware bundling defense-evasion capability with the payload. An analyzed sample was identified as a Go binary. Reported associated filenames include a.exe and r49hz.exe. Published hashes for one sample are SHA-256 1942510d3b5691819636067ec89b7b7bb18f784d819060d687fc0248dbed5047, SHA-1 2f859eeaa01238ed704fe504470186904dc59629, and MD5 e8c19bf10d044fe448a60e3fa0f60d58. A notable implementation flaw has been reported in Obscura’s encryption process: files larger than 1 GB may become permanently unrecoverable because the malware fails to write the encrypted temporary key to the file footer, meaning data may remain undecryptable regardless of ransom payment.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

12 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1189Drive-by CompromiseEvidence1

...эксплойтов, вредоносной рекламы, веб-инжектов, фальшивых обновлений...

T1566PhishingEvidence1

с помощью email-спама и вредоносных вложений

Execution

3 techniques
T1059.003Windows Command ShellEvidence1

cmd.exe /c vssadmin delete shadows /all /quiet

T1203Exploitation for Client ExecutionEvidence1

...эксплойтов...

T1204.002Malicious FileEvidence1

с помощью email-спама и вредоносных вложений, обманных загрузок

Privilege Escalation

1 technique
T1068Exploitation for Privilege EscalationEvidence1

Используется техника BYOVD (Bring Your Own Verificant Driver) для обхода средств защиты.

Lateral Movement

1 technique
T1021.001Remote Desktop ProtocolEvidence1

Может распространяться путём взлома через незащищенную конфигурацию RDP

Command and Control

1 technique
T1105Ingress Tool TransferEvidence1

...перепакованных и заражённых инсталляторов.

Impact

4 techniques
T1486Data Encrypted for ImpactEvidence2

Nightspire, a closed-group operation with OneDrive cloud encryption capability, expanded by 183% from 29 victims to 82...

T1489Service StopEvidence1

Завершает множество процессов, которые могут помешать шифрованию.

T1490Inhibit System RecoveryEvidence1

Удаляет теневые копии файлов с помощью команды: cmd.exe /c vssadmin delete shadows /all /quiet

T1657Financial TheftEvidence1

All information has been stolen... If there is no response, all stolen information will be distributed.

INDICATORS OF COMPROMISE

IOCs tracked for this family

4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
1 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
3 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
hash.sha1●●●●●●●●●●●●View more in app3 months ago
hash.sha256●●●●●●●●●●●●View more in app3 months ago
domain●●●●●●●●●●●●View more in app3 months ago
hash.md5●●●●●●●●●●●●View more in app3 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching4

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping12

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.