Sordeal Group, also known as Sordeal and sordeal_group, is a financially motivated malware-as-a-service operator active since at least early 2023. Its offerings include the Nova information stealer, the paid Nova Sentinel builder, and MALICORD. The group promotes its tools through online repositories and Telegram, including free activation-key giveaways and trials intended to attract customers. Nova targets Windows systems and collects system information, screenshots, browser data, application credentials, and stored passwords. Its targets include Chrome, Edge, Firefox, WinSCP, and ICQ. It uses Windows DPAPI to decrypt protected data, establishes persistence through the startup folder, and modifies logging settings to reduce visibility into kernel-level activity. Its execution chain uses NSIS packaging and AutoIT to interact with Windows APIs and create suspended processes for code injection. Sordeal also developed Discord application-injection code that stole session tokens and victim information, sending copies both to the customer and to infrastructure controlled by Sordeal.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
50 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Developer/operator behind NOVABLIGHT, a NodeJS-based Malware-as-a-Service infostealer sold via Telegram, Discord, and online storefronts. The group is also linked in the content to Nova Sentinel and MALICORD, and supports payload building, dashboards, and exfiltration infrastructure for customers.
French-language-proficient malware-as-a-service operator responsible for developing and selling the NodeJS/Electron-based NOVABLIGHT information stealer. The group distributes licenses and payload-building capability via Telegram and Discord, supports stolen-data dashboards, and enables credential theft, crypto-address clipboard substitution, Electron application injection, system sabotage, and multi-channel exfiltration.
Sordeal develops and distributes information stealers through a malware-as-a-service model. Active since early 2023, with increased activity observed from September 2023, the operators promote adoption through free builder keys and trials. Their Nova malware steals credentials and system information while using persistence, code injection, and defense-evasion techniques. Earlier Discord-stealing code also sent a copy of stolen information to Sordeal's own panel. At publication, expanded Discord theft and cryptocurrency-wallet injection capabilities were under development rather than confirmed deployed.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.