RALord, later also referenced as NOVA or Nova, is an emerging ransomware and extortion operation first observed in early 2025. Reporting consistently links the two names, with NOVA described as a rebrand or affiliate program associated with the original RALord operation. The group has been characterized both as a ransomware-as-a-service effort recruiting affiliates and as a relatively closed operation in which operators retain significant control over ransomware deployment after initial access is obtained. RALord/NOVA conducts double-extortion operations, combining file encryption with data theft and leak-site pressure. Its leak infrastructure has been used to publish victim claims and countdown timers intended to coerce payment. The group has recruited participants on criminal forums and has advertised partnership or affiliate arrangements under the NOVA branding. Victimology indicates activity across multiple regions, with repeated reporting of victims in Europe and Latin America and later reporting highlighting attacks against MSPs, telecommunications providers, and organizations in the Middle East. Early named victim sectors included education, engineering, manufacturing, tourism, and agriculture-related enterprises. Broader reporting also places the group among active ransomware actors targeting construction, IT services and consulting, healthcare, software development, legal services, industrial machinery, and real-estate-related organizations through publicly claimed incidents. For initial access, RALord has been assessed to prioritize internet-facing perimeter and network security technologies, particularly products from Fortinet, SonicWall, and Cisco. Reported access methods include brute-force activity and exploitation of known vulnerabilities affecting edge devices, authentication services, and vulnerable web applications. The operation has also been identified among the more active ransomware groups targeting MSPs and telecom providers in the first half of 2025. Technical analysis of the ransomware indicates a Rust-based payload using hybrid cryptography and multithreaded file encryption. Observed behavior includes file and directory enumeration and encryption of files within the current working directory tree rather than indiscriminate full-disk encryption by default. Public reporting also noted implementation flaws, including dependency issues and self-encryption mistakes affecting ransom-note handling. Separate analysis identified code-pattern similarities with FunkSec, suggesting possible code reuse, collaboration, or shared developer lineage, although the precise relationship remains unconfirmed. Operational reporting around NOVA also indicates affiliate governance typical of Russian-speaking cybercriminal ecosystems. In one widely discussed case involving a CIS-linked victim, the operators reportedly apologized, banned the responsible affiliate, and stated that data would not be leaked, reflecting the longstanding norm among many such groups of avoiding domestic or CIS targets. Overall, RALord/NOVA is best understood as a financially motivated ransomware brand that emerged during the fragmented 2025 ransomware landscape, using affiliate recruitment, double extortion, targeting of exposed edge infrastructure, and rebranding under NOVA to expand its presence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in quarterly rankings only.
Ransomware group showing week-over-week growth, doubling its number of public claims.
Ransomware group listed among the most active groups in week 29 of 2026 with 7 claimed victims.
Ransomware group maintaining a stable weekly presence with 10 claimed victims.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.