Nova is a financially motivated ransomware-as-a-service (RaaS) operation that emerged publicly as RALord in March 2025 and completed a rebrand to Nova by late April 2025. Also known as Nova RaaS, it operates an affiliate model and has recruited personnel with penetration-testing, vulnerability-exploitation, Python, and Rust experience. The recruitment persona ForLord has been associated with the RALord/Nova operation. Nova uses a Rust-based ransomware payload and conducts double-extortion operations: it encrypts victim data, exfiltrates data, and threatens publication through a dedicated leak site if payment is not made. Its victim communications have offered proof of compromise, file listings, samples of stolen information, and limited decryption demonstrations. Nova maintains infrastructure for affiliate recruitment and management, including encrypted communications capabilities. The operation has claimed victims across numerous countries and sectors, with reported targeting of technology and managed-service providers, manufacturing and industrial organizations, healthcare providers, educational institutions, financial-services entities, public-sector organizations, telecommunications, and logistics. Publicly reported activity includes attacks against Indonesian public and healthcare institutions, and victim claims in the Americas, Europe, and Asia. Nova advertised an AI assistant on its leak site, but the existence or operational use of that capability has not been independently verified.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware-as-a-service operation that rebranded from RALord to Nova in April 2025. It operates an affiliate program, Rust-based ransomware encryptor, Tor-hosted leak site, and encrypted communications infrastructure. The operation combines encryption with data theft and extortion, and recruits affiliates with penetration-testing and vulnerability-exploitation experience.
A ransomware operation that announced an AI assistant on its leak site, though the content notes that the claimed capability has not been independently confirmed.
A ransomware group listed among the top active groups and specifically described as targeting Indonesian public-sector and healthcare organizations.
A ransomware group mentioned among the active groups targeting educational institutions in the reporting period.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.