Nova is a cross-platform ransomware family associated with a ransomware-as-a-service operation formerly known as RALord. The operation was first observed in late March 2025 and rebranded as Nova in April 2025. It uses double extortion, combining file encryption with sensitive-data theft and threats of public disclosure. Its Tor-hosted leak and negotiation infrastructure publishes victim profiles, countdowns, and evidence of stolen data. Affiliates receive access to payload builders and infrastructure in exchange for a share of ransom proceeds.
Nova supports Windows, Linux, and VMware ESXi environments, including a Rust-based payload variant. Affiliate intrusions use compromised VPN or RDP credentials, initial-access brokers, spearphishing, and exploitation of public-facing applications. Associated activity includes credential harvesting, persistence, privilege escalation, network discovery, and lateral movement. Deployment workflows can disable security processes, force Windows into Safe Mode, delete shadow copies, and disrupt backup services to impede detection and recovery. Sensitive data is exfiltrated before encryption.
The operation has targeted organizations across multiple continents, including healthcare, education, hospitality, IT services, construction, and agriculture. Its attack on the Dutch laboratory Clinical Diagnostics exposed sensitive patient information on a large scale. Nova is also a name used by other malware, including information stealers and cryptocurrency drainers; those namesakes should not be conflated with the RALord-associated ransomware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Nova offers AI chatbots for negotiations with some automation and tools but nothing advanced, like network discovery, encryption modes, or EDR killers.
In this report, we will discuss the behavior of their full version infostealer known as Nova.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
“Keenadu was also distributed via modified popular apps from unofficial stores and even Google Play, where trojanized smart camera apps with over 300,000 downloads…”
The malware tries to load missing DLLs and creates processes in suspended mode for code injection.
win32snapshot[.]exe (md5: 13639e7f3707d05d90798d21d404eccc), sets the “Circular Kernel Context Logger” registry key value to “0”. As a result, events related to kernel-mode operations, system calls, and other low-level activities will no longer be recorded.
It abuses the inbuilt Windows utility Data Protection Application Programming Interface (DPAPI) to perform data decryption. This API contains a class called ProtectedData, that contains two wrappers: “Protect” and “Unprotect.” The infostealer passes a byte array of the encrypted data to the “Unprotect” wrapper, which subsequently returns a byte array of decrypted data.
The malware targets multiple browsers, including the most used Edge, Chrome and Firefox. Additionally, the malware invokes reg.exe to harvest information related to WinSCP, targeting stored sessions and passwords.
The Chrome configuration is stored in the local AppData directory in a file called “Local State”. This configuration contains an entry called “os_crypt,” which has a sub-entry called “encrypted_key.” The “encrypted_key” is used by Chrome to encrypt saved login data. Below we can see that the malware tries to access that.
The malware uses this open-source utility to capture the screenshot of the target machine.
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation mentioned for an unverified claim that it offers an AI assistant on its leak site.
macOS information stealer distributed through malicious GitHub repositories during the macOS branch of Operation RepoGhost.
Ransomware family/group cited as one of the active actors targeting educational institutions.
국내를 표적으로 삼은 랜섬웨어 그룹 중 하나로 언급된다.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.