Nova is a ransomware and extortion threat actor active by at least mid-2026 and observed among the more active emerging groups in the broader ransomware ecosystem. Public reporting placed Nova among the notable ransomware groups in June 2026, with dozens of victim postings, and also identified it as one of the groups affecting organizations in South Korea during Q2 2026. Nova has targeted organizations across multiple countries and sectors, including information technology and managed services, financial services, healthcare, education, telecommunications, logistics, media, retail, and public-sector entities. Reported victims include technology providers, a finance-sector public institution, a university hospital, a university, telecommunications-related organizations, logistics firms, and a state government entity, indicating broad opportunistic targeting rather than a narrowly specialized victim profile. Operationally, Nova is associated with ransomware intrusions accompanied by data theft and extortion. Multiple victim cases describe claims of stolen data, offers to provide file trees and sample data as proof of compromise, and offers to decrypt sample files, which is consistent with double-extortion tradecraft combining encryption pressure with exfiltration-based coercion. Nova has also been linked to leak-site activity and public victim shaming. An unusual reported behavior was a public apology posted to one victim organization, but this does not materially change the group’s overall criminal profile. Aliases observed for the actor include nova_group and nova_raas. Available information supports characterization of Nova as a financially motivated cybercriminal ransomware actor. High-confidence public reporting does not establish a specific national origin for the group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack and associated data theft/extortion against SistNet, including providing a tree and samples from stolen data and offering a decrypt sample upon contact with their support department.
Conducting a ransomware attack and data theft/extortion against Center Of Information Technologies In Finance Public Institution, including providing a tree and samples of stolen data to pressure the victim to contact support.
Conducting a ransomware attack and data theft/extortion operation against Digital Edge, with claims of encrypted devices, stolen data, and offers to provide samples and decrypt a sample upon contact.
Conducting a ransomware attack and associated data theft against VNSO; the content states the group stole client data and provided a tree and samples of stolen data after contact with the support department.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.