Ransomware Intelligence

obscura

Ransomware group profile

31Victims
58Impact score

Description

Obscura is a sophisticated threat group known for its diverse tactics and wide-ranging targets. They operate across various sectors, employing advanced techniques to compromise systems and extract sensitive data. Their activities have significant implications for affected organizations, often resulting in financial and operational disruption.

Key insights

  • Utilizes phishing and social engineering for initial access.
  • Targets a wide array of sectors including construction, real estate, and public administration.
  • Employs ransomware and data exfiltration tactics to maximize impact.
  • Operates internationally, with notable activity in both Europe and North America.
  • Engages in supply chain attacks to infiltrate organizations indirectly.
  • Adapts quickly to changes in security measures, demonstrating high resilience.

Threat Level & Status Breakdown

For obscura · Based on incidents in selected period

2.6threat level
Aggressiveness5/ 10
Lethality0.8/ 10
Criticality1.9/ 10

Status Breakdown

Data Leaked16.1%5
Claimed25.8%8
First seenJul 2025
Last seenJan 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 2, 2026

Recent activity

Monthly attack count for obscura in the selected period

31Total attacks
9peak in Dec
4.4avg / month
↑ 2 vs first month
JulAugSepOctNovDecJan036912

Intelligence

IOCs, YARA/Sigma rules, and related families for obscura

  1. d520d06d78afcad2e03842cb8db4622d18b92739e89dfb8dadf5743f30dcd903
  2. e75e5778e71e062ce4a7af673f0b2513854d2367fee0f01a26c0c998863bdf6e
  3. 1942510d3b5691819636067ec89b7b7bb18f784d819060d687fc0248dbed5047
  4. eae09889399fe4fb8e78b114dba0527de913d12fb1802944a88ed136e3e90577
  5. 94f73b5dc06ba6705fcef3e759413a747049c2949a0c2e44afc03b2f9989cf73
View full IOC feed500 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for obscura

Other

T1486

T1486

T1490

T1490

T1078

T1078

T1021

T1021

T1562

T1562

T1059

T1059

T1547

T1547

T1021.001

T1021.001

T1106

T1106

T1203

T1203

T1012

T1012

T1080

T1080

Victims(31)

CompanyDomainCountryIndustryStatusDiscovered
Thai Petroleum & Tradingthaipet.comTH ThailandManufacturing
Claimed
5 months ago
STC Concrete Productstc.co.thTH ThailandOther
Unknown
5 months ago
REDtoneredtone.comMY MalaysiaTechnology
Unknown
5 months ago
Revoilrevoil.grGR GreeceEnergy & Utilities
Unknown
5 months ago
[Redacted] #1927TH ThailandEnergy & Utilities
Unknown
5 months ago
Trend Import Exporttrend.roRO RomaniaTechnology
Unknown
5 months ago
k*m**w.comk*m**w.comNA NamibiaTransportation
Unknown
6 months ago
CleverPowercleverpower.euDK DenmarkEnergy & Utilities
Unknown
5 months ago
cle**rp**er.eucle**rp**er.euNA NamibiaEnergy & Utilities
Unknown
6 months ago
New Obscura 2.0!fbi.govUS United StatesGovernment & Defense
Unknown
6 months ago
StanleyCo Malaysiastanleyco.com.myMY MalaysiaProfessional Services
Unknown
6 months ago
Startek Engineering Inc.startek-eng.comTW TaiwanTechnology
Unknown
6 months ago
ACE Forwardingaceforwarding.comUS United StatesTransportation
Unknown
6 months ago
New Toyo International Holdings Ltdnewtoyo.comSG SingaporeManufacturing
Data Leaked
7 months ago
Thompson Dorfman Sweatmantdslaw.comCA CanadaProfessional Services
Data Leaked
7 months ago
Federal Auto Holdings Berhadfederalauto.com.myMY MalaysiaTransportation
Data Leaked
7 months ago
Cape Dara Resort Pattayacapedarapattaya.comTH ThailandHospitality
Data Leaked
8 months ago
relationmedia.dkDK DenmarkTechnology
Claimed
8 months ago
thefixingcompany.comIE IrelandOther
Claimed
8 months ago
eastdesign.com.myMY MalaysiaProfessional Services
Claimed
8 months ago

Page 1 of 2