Sordeal is a malware-as-a-service operator active since at least early 2023 and associated with the infostealer families Nova, Nova Sentinel, MALICORD, and likely NOVABLIGHT. The group appears to be French-speaking and has marketed its tooling through Telegram, Discord, GitHub, and commercial storefronts, using free trials, public builders, and referral incentives to broaden adoption among lower-tier threat actors. Sordeal’s operations center on information theft and post-compromise collection. Nova is a Windows infostealer that profiles infected hosts, gathers system information, steals browser credentials and application data, abuses DPAPI to decrypt protected data, captures screenshots, and harvests WinSCP sessions and passwords. The malware establishes persistence through startup execution and modifies the Windows registry for both persistence and stealth. Reported defense-evasion behavior includes disabling kernel-related logging visibility and use of packing, suspended-process creation, and code injection techniques. Earlier Sordeal activity also included Discord-focused theft through malicious injection into Electron application components to capture Discord session tokens and victim information. The group’s more advanced ecosystem includes NOVABLIGHT, a modular NodeJS and Electron-based MaaS stealer with broader capabilities. Attributed functionality includes anti-analysis checks, browser and wallet theft, Electron application injection, clipboard hijacking, webcam capture, Wi-Fi password theft, exfiltration through multiple channels, and disruptive host actions such as attempts to disable security controls, recovery features, and network connectivity. Sordeal has also been linked to ongoing development of Discord injection features aimed at account takeover and to code-injection capabilities targeting cryptocurrency wallets such as Exodus and Atomic Wallet. Sordeal’s tradecraft spans initial delivery via lure installers, credential and session theft, persistence, defense evasion, process injection, exfiltration, and crypto-focused theft. Its dominant motivation is financial gain through sale and operation of commodity infostealer tooling and theft-enabling services.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
31 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
49 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Developer/operator behind NOVABLIGHT, a NodeJS-based Malware-as-a-Service infostealer sold via Telegram, Discord, and online storefronts. The group is also linked in the content to Nova Sentinel and MALICORD, and supports payload building, dashboards, and exfiltration infrastructure for customers.
MaaS operators developing and distributing the Nova infostealer, using free key giveaways and public repositories to expand adoption. Their malware focuses on persistence, credential theft, browser and application data harvesting, Discord injection, and emerging crypto-wallet targeting, while employing anti-forensic and defense-evasion techniques.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.