Skip to main content
Mallory
1 malware familyExploits CVEs in the wild

Nova

Also known asnova

Nova is a ransomware-as-a-service (RaaS) group, formerly known as RALord, and is described as tied to the RALord network. The group uses double-extortion tactics, with reporting stating it encrypts victim files and threatens to leak stolen data if payment is not made. One report states the ransomware is based on Babuk source code. Known aliases and related names directly mentioned in the content include RALord, RALord-RaaS, and Nova; additional names listed in reporting about the group’s administrators or recruiters include AlexL101m3, ForLord, jhonkarry, and Alex/Aлексей. The content places Nova among active ransomware operators in 2025-2026 and repeatedly describes it as targeting organizations in healthcare, manufacturing, education, professional services, and industrial sectors. Reported victims or claimed victims mentioned in the content include Clinical Diagnostics in the Netherlands, FysioRoadmap, KPMG Netherlands, a South Korean industrial equipment manufacturer, and a South Korean university. Quorum Cyber reporting cited in the content says Nova accounted for 10% of observed ransomware activity affecting higher education during the measured period. Other reporting cited in the content says Nova continued publishing victims from healthcare, manufacturing, and education. The group is linked in the content to several incidents in the Netherlands. Nova was reported to have attacked Clinical Diagnostics, affecting more than 850,000 people, and FysioRoadmap, exposing data from more than 20,000 patients. Multiple items state Nova claimed KPMG Netherlands on its leak site and threatened publication within 10 days, although KPMG later stated that its IT infrastructure and security systems had not been compromised. The content also states Nova threatened to leak data stolen from a lab and that Nova exfiltrated patient data during a July ransomware attack. Operationally, the content describes Nova as maintaining dark web leak infrastructure and, in one report, multiple Tor-based command-and-control or leak-site elements using standardized uvicorn-based backend deployment. Another report states Nova’s infrastructure was exposed due to network-configuration mistakes that revealed backend addresses and additional attack surfaces. The content also notes Nova’s leak site changes frequently. The content describes Nova as active in underground criminal ecosystems, including use of the RAMP forum, where Nova publicly chastised another group, Radiant, for leaking children’s data. Separate reporting states Nova also chastised an affiliate after an accidental hit on Eriell Group, a CIS-linked business; the content says Nova publicly backtracked, claimed encryption did not occur and data was not published, and reportedly banned the responsible operator. Reporting cited in the content also says that after the RAMP takedown, groups such as Nova were reportedly shifting activity toward Rehub. Overall, the content consistently characterizes Nova as a financially motivated ransomware operator rather than a nation-state actor.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Energy

Where they target

Geographies tied to known operations.

  • 🇺🇿 Uzbekistan
  • 🇷🇺 Russia
MITRE ATT&CK

Tradecraft

9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

9 of 15 tactics13 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1589×2
Gather Victim Identity Information
TA0001
Initial Access
1 technique
T1078
Valid Accounts
TA0003
Persistence
1 technique
T1078
Valid Accounts
TA0004
Privilege Escalation
1 technique
T1078
Valid Accounts
TA0005
Stealth
1 technique
T1078
Valid Accounts
TA0006
Credential Access
1 technique
T1056
Input Capture
TA0009
Collection
2 techniques
T1056
Input Capture
T1213
Data from Information Repositories
TA0010
Exfiltration
3 techniques
T1020×2
Automated Exfiltration
T1041×4
Exfiltration Over C2 Channel
T1567×4
Exfiltration Over Web Service
TA0040
Impact
2 techniques
T1486×7
Data Encrypted for Impact
T1657×3
Financial Theft
IOCS

Observables

1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping9

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs1

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables1

Domains, IPs, and hashes tied to this actor, refreshed continuously.