RA Group is a ransomware-as-a-service operation first observed in April 2023 and associated with attacks against VMware ESXi environments. The group publicly listed victims on a leak site and, in its early observed activity, targeted organizations in the United States, South Korea, and Taiwan. RA Group has been described as using ransomware derived from the leaked Babuk source code, placing it among the wave of post-Babuk ransomware operations that adapted Linux and ESXi-focused encryption capabilities. The group is part of an evolving ransomware lineage. RA Group was reported to have rebranded as RA World in early 2024, and RaLord has been characterized as a successor or offshoot of the former RA Group. Later reporting links the broader lineage to the Nova ransomware operation, which has been described as a mature criminal RaaS enterprise built around the RaLord family. High-confidence reporting supports continuity of branding and tooling lineage across RA Group, RA World, and RaLord/Nova, but not a nation-state designation for RA Group itself. RA Group’s known behavior is consistent with financially motivated extortion operations: compromising victim environments, encrypting systems including ESXi-hosted infrastructure, stealing data, and pressuring victims through public leak-site exposure. Its activity aligns with broader ransomware tradecraft centered on initial access, persistence, defense evasion, post-exploitation, exfiltration, and encryption-backed extortion. Reporting also places RA Group among ransomware operations that leveraged Babuk-derived code during the first half of 2023.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 malware families attributed to this actor across reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a predecessor lineage to the RaLord ransomware family; mentioned only in the context of Nova being a successor/offshoot rather than as an active operator in this incident.
Referenced as a predecessor lineage to the RaLord ransomware family; mentioned only in the context of Nova being a successor/offshoot rather than as an active operator in this incident.
RaaS group rebranded to RA World and linked to China-based threat actors through PlugX overlap with Mustang Panda.
Ransomware actor listed as active in Q1 2025.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.