RALord is a Rust-based ransomware family and associated ransomware-as-a-service operation first observed in 2025. It has also been referenced in later reporting under the Nova branding, reflecting rebranding or affiliate-program evolution within the same criminal ecosystem. The operation uses double extortion, combining file encryption with data theft and leak-site pressure, and has targeted organizations in sectors including healthcare, education, engineering, manufacturing, telecommunications, construction, and tourism, with notable activity affecting victims in Latin America as well as Europe.
RALord is deployed as an operator- or affiliate-enabled encryptor after initial compromise. Reported intrusion paths include attacks against internet-facing perimeter infrastructure and network security products, especially appliances from major enterprise vendors, as well as brute-force activity and exploitation of known vulnerabilities in edge devices, authentication services, and exposed web applications. The group has recruited affiliates in criminal forums and used private messengers for victim and operator communications.
Technically, the malware is written in Rust and performs file and directory enumeration before encrypting data. Reported samples recursively encrypt files within the current working directory tree rather than automatically traversing the entire disk by default. RALord uses a hybrid cryptographic design that includes system-generated randomness, a custom key-wrapping routine, and XChaCha20-Poly1305 for file encryption. It creates ransom notes and appends a distinctive encrypted-file extension. Public reporting also associates the broader Nova branding with negotiated extortion workflows rather than fixed payment instructions.
Observed tradecraft supports both encryption and exfiltration-driven extortion. The operation maintains leak infrastructure on Tor and uses countdown-based pressure tactics to coerce payment. Reporting on Nova-linked incidents indicates theft of sensitive data and threats of public release even where encryption outcomes were disputed. Code-pattern similarities with FunkSec have been noted, suggesting possible code reuse, shared development lineage, or collaboration, although the precise relationship remains unconfirmed.
Implementation flaws have also been reported in early samples, including dependency issues that can cause execution failure on some Windows systems and extension-handling mistakes that may interfere with the malware’s own ransom-note logic. Despite such immaturity indicators, RALord/Nova has been treated as an active profit-motivated criminal ransomware operation rather than a state-linked campaign.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Nova is a relative newcomer that some security researchers say distributes the RALord ransomware to encrypt files, exfiltrate sensitive data and use double extortion tactics to pressure victims."
Nova is a relative newcomer that some security researchers say distributes the RALord ransomware to encrypt files, exfiltrate sensitive data and use double extortion tactics to pressure victims.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware operation whose industrial victim claims increased in Q2 2026.
Ransomware operation discussed in the context of an affiliate mistakenly targeting a CIS-based company, then apologizing and offering recovery assistance.
Ransomware family/brand involved in rebranding (NOVA/RALord) with common RaaS-style extension and ransom-note naming conventions.
Ransomware/RaaS brand noted for rebranding/identity fluidity (NOVA/RALord), with common RaaS-style extension and ransom-note naming patterns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.