Nova is a financially motivated ransomware-as-a-service operation, also tracked as Nova Group and Nova RaaS, that publicly emerged as RALord in March 2025 and rebranded to Nova in spring 2025. It uses a Rust-based ransomware payload and conducts double-extortion attacks, combining file encryption with data theft and threats to publish stolen information on a Tor-hosted leak site. Its affiliate program provides recruitment infrastructure, an affiliate panel, and encrypted communications channels. The operation advertised a revenue-sharing arrangement under which affiliates retained approximately 85% of ransom payments. ForLord is a recruitment persona associated with the operation. Nova targets organizations internationally across information technology, manufacturing, healthcare, education, professional services, finance, media, tourism, and government. Its claimed victims include managed IT and cybersecurity service providers, Indonesian healthcare and public institutions, and the Kedah state government in Malaysia. In 2025, Nova sought to purchase VPN access to a US or European healthcare organization with at least $500 million in revenue, demonstrating deliberate interest in high-revenue healthcare targets. Extortion communications commonly offer stolen-data samples, file inventories, and sample decryption to substantiate demands. Nova's public victim listings establish its targeting patterns but do not independently confirm every claimed compromise. Its geographic origin and operator identities have not been established at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware-as-a-service operation that rebranded from RALord to Nova in April 2025. It operates an affiliate program, Rust-based ransomware encryptor, Tor-hosted leak site, and encrypted communications infrastructure. The operation combines encryption with data theft and extortion, and recruits affiliates with penetration-testing and vulnerability-exploitation experience.
A ransomware operation that announced an AI assistant on its leak site, though the content notes that the claimed capability has not been independently confirmed.
A ransomware group listed among the top active groups and specifically described as targeting Indonesian public-sector and healthcare organizations.
A ransomware group mentioned among the active groups targeting educational institutions in the reporting period.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.