Ransomware Group intelligence
Obscura
InactiveTrack Obscura with 34 published victims and 1 known leak locations in a single intelligence view.
Overview
Obscura is tracked by Breach House as a ransomware group with 34 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 57m ago | obscurad3aphckihv7wptdxvdnl5emma6t3vikcf3c5oiiqndq6y6xad.onion |
Top Activity Sectors (10)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Obscura, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: obscura executes malicious commands via PowerShell scripts to stage payloads and manipulate system behavior.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: obscura disables antivirus and monitoring tools by terminating security processes and modifying system configurations.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: obscura encodes victim files with custom symmetric encryption routines before demanding payment.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: obscura deletes Volume Shadow Copies and backup directories via command-line utilities to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1003.001 LSASS Memory Credential Access
What they do: obscura accesses and dumps LSASS memory to steal credentials for lateral movement and persistence.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1049 System Network Connections Discovery Discovery
What they do: obscura enumerates network connections and service ports to identify high-value targets for encryption.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1135 Network Share Discovery Discovery
What they do: obscura scans network shares using native tools to identify victim file structures and encryption targets.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: obscura moves laterally through SMB/Windows Admin Shares to compromise additional networked systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: obscura encrypts victim files using custom ransomware binaries targeting critical business and personal data.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: obscura halts system recovery processes by stopping critical services and disrupting backup restoration mechanisms.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README-OBSCURA.txt
Good day! Your company has failed a simple penetration test. >> Your network has been completely encrypted by our software. Our ransomware virus uses advanced cryptography technology that will make it very difficult for you to recover your information. >> All information has been stolen. We have stolen all information from all devices on your network, including NAS. The data includes but is not limited to: employee passport details, internal documentation, financial documents, and so on. >> You have about 240 hours to respond. If there is no response, all stolen information will be distributed. We are waiting for you to decide to write to us, and we will be happy to negotiate a ransom price with you. By paying the ransom, you will also receive: 1) a report on how we infiltrated your network 2) instructions + software that decrypts all files 3) our assistance in recovery, if needed. >> They will not help you; they are your enemies. Recovery agencies, the police, and other services will NOT HELP you. Agencies want your money, but they do not know how to negotiate. If you think you can restore your infrastructure from external backups that we did not access, we warn you: 1) The laws of any country impose huge fines on companies for information leaks. 2) Playing against us will not work in your favor. We will gladly wipe every one of your servers and computers. When you write to us, we expect to hear from you who you are and what your relationship to the company is. Your ID: [snip] TOX: AE55FC0EB1C25A5B081650108F9081E236DECE1CE08D2E185A6F15B9FB48E700210BED374643 Blog: http://obscurad3aphckihv7wptdxvdnl5emma6t3vikcf3c5oiiqndq6y6xad.onion/ Obscura. 2025.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (34)
Search, filter and paginate the victim timeline for Obscura. Showing 1–34 of 34.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Revoil id25431 View details | Greece | Energy | — | |
|
Revoil trades fuels and lubricants through its network of petrol stations, which consists of more than 500 petrol stations across Greece. |
|||||
| Ransomware | CleverPower id25414 View details | Denmark | Energy | — | |
|
Technology leader for modern energy infrastructure |
|||||
| Ransomware | Trend Import Export id25413 View details | Romania | Communication / Marketing | — | |
|
IT company specializing in enterprise solutions and hardware |
|||||
| Ransomware | Thai Petroleum & Trading id25412 View details | Thailand | Energy | — | |
|
thaipet.com is a Thailand-based company associated with the Energy sector, a field that covers power, fuels, and related energy services in the Thai market. Thailand’s energy landscape includes electricity generation, renewable deployment, and broader fuel and power-system planning, with national policy focused on diversification and efficiency. The domain name suggests a branded commercial presence, but no additional public corporate profile was available in the provided sources to confirm a more specific offering. It was listed as a ransomware victim associated with obscura. |
|||||
| Ransomware | [Redacted] #1927 id25715 View details | Thailand | Other | — | |
|
[Redacted] |
|||||
| Ransomware | STC Concrete Product id25411 View details | Thailand | Communication / Marketing | — | |
|
STC Concrete Product Public Company Limited engages in the manufacture and distribution of precast concrete products in Thailand. |
|||||
| Ransomware | REDtone id25410 View details | Malaysia | Telecommunications | — | |
|
REDtone International is a telecommunications service provider for to niche markets. |
|||||
| Ransomware | cle**rp**er.eu id24793 View details | Construction / Real Estate | — | ||
|
Technology leader for modern energy infrastructure |
|||||
| Ransomware | k*m**w.com id24777 View details | Construction / Real Estate | — | ||
|
Transportation & Warehousing |
|||||
| Ransomware | ACE Forwarding id24739 View details | United States | Transportation / Travel / Logistics | — | |
|
Ace Forwarding offers several methods of protecting your freight. Full-service crating and repackaging are available in a variety of materials. Our full time staff of carpenters will custom-tailor crating and packaging to fit your specific needs. |
|||||
| Ransomware | Startek Engineering Inc. id24738 View details | Taiwan, Province of China | Communication / Marketing | — | |
|
STARTEK is a worldwide leading company in the fingerprint identification industry, dedicated to developing and providing consumer-ready fingerprint identification products, biometric fingerprint sensors and modules. Established in 1989 at Hsinchu Science Industrial Park, Taiwan, the company has a long history and rich experience in the Biometric fingerprinting field, and continues to be a strong player in the evolution of fingerprint technology development and applications. Startek’s patented proprietary fingerprint algorithm technology follows the ISO/IEC 19794-2 standard and provides maximum accuracy, performance, and reliability. |
|||||
| Ransomware | StanleyCo Malaysia id24737 View details | Malaysia | Services | — | |
|
StanleyCo Malaysia provides expert accounting, tax advisory, company incorporation, and compliance services for local and foreign businesses in Malaysia. |
|||||
| Ransomware | New Obscura 2.0! id24736 View details | Communication / Marketing | — | ||
|
We present the new version of Obscura 2.0. Faster encryption mechanisms, bugs fixed in the first version, more covert operation, and more upset companies. Now you can rent our software. You can write to us on Tox, where we will tell you about the terms and conditions. |
|||||
| Ransomware | New Toyo International Holdings Ltd id23542 View details | Singapore | Services | ||
|
Revenue: $221.7kk | Leak Size: 2 GB | Status: Pending | Time Left: 6d 17h 27m 32s |
|||||
| Ransomware | Thompson Dorfman Sweatman id23525 View details | Canada | Other | ||
|
Revenue: $31.2kk | Leak Size: 250 GB | Status: Pending | Time Left: 8d 3h 57m 25s |
|||||
| Ransomware | Federal Auto Holdings Berhad id23460 View details | Malaysia | Public Sector | ||
|
Revenue: $41.8kk | Leak Size: 6 GB | Status: Pending | Time Left: 7d 18h 57m 21s |
|||||
| Ransomware | Cape Dara Resort Pattaya id23236 View details | Thailand | Hospitality / Food & Beverage / Tourism | ||
|
Revenue: $25.2kk | Leak Size: 80 GB | Status: Pending | Time Left: 8d 6h 57m 24s |
|||||
| Ransomware | relationmedia.dk id23010 View details | Denmark | Communication / Marketing | ||
|
Revenue: $<5kk | Leak Size: xx GB | Status: Published |
|||||
| Ransomware | meamargroup.com id23009 View details | Egypt | Services | ||
|
Revenue: $30kk | Leak Size: xx GB | Status: Published |
|||||
| Ransomware | plazadental.com id23008 View details | United States | Healthcare / Pharma | ||
|
Revenue: $<5kk | Leak Size: xx GB | Status: Published |
|||||
| Ransomware | heavenly-dental.com id23007 View details | United States | Healthcare / Pharma | ||
|
Revenue: $<5kk | Leak Size: xx GB | Status: Published |
|||||
| Ransomware | thefixingcompany.com id23006 View details | Ireland | Services | ||
|
Revenue: $<5kk | Leak Size: xx GB | Status: Published |
|||||
| Ransomware | eastdesign.com.my id23005 View details | Malaysia | Other | ||
|
Revenue: $<5kk | Leak Size: xx GB | Status: Published |
|||||
| Ransomware | espectral.pt id23004 View details | Portugal | Other | ||
|
Revenue: $<5kk | Leak Size: xx GB | Status: Published |
|||||
| Ransomware | michigancityin.gov id23003 View details | United States | Public Sector | ||
|
Revenue: ?? | Leak Size: 450 GB | Status: Published |
|||||
| Ransomware | EAST Design Architect Sdn. Bhd id22497 View details | Malaysia | Communication / Marketing | ||
|
Design agency in Malaysia, Penang |
|||||
| Ransomware | Espectral id22496 View details | Portugal | Communication / Marketing | ||
|
Espectral specializes in providing testing and measurement equipment, focusing on sectors such as telecommunications, finance, healthcare, and education. Their product offerings include calibration services for various parameters, general electronics, and advanced testing equipment for protocols like PCI Express and USB. Established in 1987, the company aims to be a partner for future technological advancements, particularly in 5G and avionics. They cater to a diverse clientele, including government, industry, and laboratories. |
|||||
| Ransomware | RelationMedia A/S id22150 View details | Denmark | Communication / Marketing | ||
|
RelationMedia A/S is the leading agency in Denmark within sales forces, merchandising, marketing, data collection, sampling, product presentation and events. |
|||||
| Ransomware | Rulmaksan Makina id22147 View details | Türkiye | Services | ||
|
Rulmaksan Makina is a company that operates in the Consumer Services industry. |
|||||
| Ransomware | The Fixing Company id22146 View details | Ireland | Construction / Real Estate | ||
|
The Fixing Company is an Irish provider of premium fixing solutions specifically designed for the construction industry. They offer a wide range of products including adhesives, building materials, safety workwear, and tools for construction professionals. The company focuses on delivering high-quality service with features such as free delivery on orders over €200 and next-day delivery in Dublin. Their intended clients include contractors and construction workers seeking reliable and efficient fixing solutions. |
|||||
| Ransomware | HeavenlyDental id22145 View details | United States | Healthcare / Pharma | ||
|
Dental clinics in San Jose |
|||||
| Ransomware | Plazadental id22144 View details | United States | Healthcare / Pharma | ||
|
Dental clinics in San Jose |
|||||
| Ransomware | WZV Warndt id22143 View details | Germany | Other | ||
|
Der WasserZweckVerband Warndt ist ein kommunaler Zweckverband, dessen Hauptaufgabe die Trinkwasserversorgung ist. Er wurde 1909 gegründet und versorgt die Stadtteile Ludweiler und Lauterbach in Völklingen sowie die Gemeinde Großrosseln |
|||||
| Ransomware | MeamarGroup id22142 View details | Egypt | Construction / Real Estate | ||
|
Specializes in real estate development, contracting, and investment services. The company aims to serve clients interested in developing and investing in residential and commercial properties. They focus on delivering quality projects and fostering customer satisfaction. With a commitment to innovation and excellence, they cater to both individual and corporate clients. |
|||||