Nova is a Windows-focused information-stealing malware operated within the Sordeal malware-as-a-service ecosystem and active since at least 2023. It is distributed as a MaaS offering and has been promoted with public builders and free keys to broaden adoption among lower-tier threat actors. Nova samples have been observed packed with an NSIS-based crypter and using a staged execution chain that drops and launches additional components, including AutoIt-based tooling, to support lower-level operations and code injection.
Once executed, Nova profiles the infected host extensively by collecting hardware and system information, querying the Windows registry, and fingerprinting the victim environment. It uses command shell and PowerShell activity heavily, attempts to load missing libraries, and creates suspended processes for injection-related behavior. For persistence, it has been observed placing a renamed payload in the Windows startup folder and modifying registry settings. It also reduces defensive visibility by disabling the Circular Kernel Context Logger and has been associated with installation of a root certificate, which can facilitate trust abuse and traffic interception.
Nova’s core function is credential and data theft. It targets browser data from Chromium-based browsers and Firefox, abuses Windows DPAPI to decrypt protected information, captures screenshots, and harvests WinSCP sessions and passwords. Development efforts have also included Discord-focused injection features aimed at stealing session tokens, backup codes, payment-card details, and account-change information, as well as code-injection capabilities against cryptocurrency wallets such as Exodus and Atomic. These behaviors place Nova firmly in the infostealer category with additional session-hijacking and crypto-theft-oriented functionality under development.
Nova is associated with the Sordeal operators, who have also used GitHub and Telegram to distribute related tooling and builders. The malware targets Windows systems and is notable for combining commodity stealer objectives with persistence, process injection, and defense-evasion measures that increase its utility for a broad criminal user base.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The report highlights a surge in malicious activities by Malware-as-a-service (MaaS) operators Sordeal – particularly with their new malware ‘Nova’ – since at least September 2023.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
“Keenadu was also distributed via modified popular apps from unofficial stores and even Google Play, where trojanized smart camera apps with over 300,000 downloads…”
The malware tries to load missing DLLs and creates processes in suspended mode for code injection.
win32snapshot[.]exe (md5: 13639e7f3707d05d90798d21d404eccc), sets the “Circular Kernel Context Logger” registry key value to “0”. As a result, events related to kernel-mode operations, system calls, and other low-level activities will no longer be recorded.
It abuses the inbuilt Windows utility Data Protection Application Programming Interface (DPAPI) to perform data decryption. This API contains a class called ProtectedData, that contains two wrappers: “Protect” and “Unprotect.” The infostealer passes a byte array of the encrypted data to the “Unprotect” wrapper, which subsequently returns a byte array of decrypted data.
The malware targets multiple browsers, including the most used Edge, Chrome and Firefox. Additionally, the malware invokes reg.exe to harvest information related to WinSCP, targeting stored sessions and passwords.
The Chrome configuration is stored in the local AppData directory in a file called “Local State”. This configuration contains an entry called “os_crypt,” which has a sub-entry called “encrypted_key.” The “encrypted_key” is used by Chrome to encrypt saved login data. Below we can see that the malware tries to access that.
The malware uses this open-source utility to capture the screenshot of the target machine.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family/group cited as one of the active actors targeting educational institutions.
국내를 표적으로 삼은 랜섬웨어 그룹 중 하나로 언급된다.
A named crypto drainer active in 2024 within the drainer-as-a-service ecosystem targeting cryptocurrency users.
Ransomware operation or affiliate referenced as tied to the RAlord network; it accidentally targeted Eriell Group and later apologized, claiming encryption did not occur and data was not published.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.