RA Group is a ransomware-as-a-service operation first observed in 2023. It has been associated with the use of Babuk-derived ransomware code and is part of an evolving ransomware lineage that later gave rise to RaLord and subsequently the Nova brand. Reporting has described RA Group as having rebranded to RA World in early 2024, while RaLord has been characterized as a successor or offshoot of the original RA Group. The cluster is therefore best understood as a criminal ransomware ecosystem with multiple related brands rather than a single static operation. RA Group has been linked in some reporting to the Chinese intrusion set commonly tracked as Mustang Panda, but the supplied material does not provide sufficient corroborated detail to treat that linkage as definitive for attribution. By contrast, the broader lineage involving RaLord and Nova is consistently characterized as a financially motivated criminal enterprise operating a mature RaaS model rather than a nation-state operation. The group’s activity fits standard modern ransomware tradecraft: compromise of victim environments, deployment of ransomware for encryption, theft of victim data, and use of leak-site pressure to extort payment. The wider lineage has targeted multiple sectors, including healthcare, information technology, manufacturing, telecommunications, education, and construction. Available reporting also places RA Group among ransomware operations active during the 2023 surge in double-extortion activity, and specifically notes its use of Babuk-derived tooling.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 malware family attributed to this actor across reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a predecessor lineage to the RaLord ransomware family; mentioned only in the context of Nova being a successor/offshoot rather than as an active operator in this incident.
Referenced as a predecessor lineage to the RaLord ransomware family; mentioned only in the context of Nova being a successor/offshoot rather than as an active operator in this incident.
RaaS group rebranded to RA World and linked to China-based threat actors through PlugX overlap with Mustang Panda.
Ransomware actor listed as active in Q1 2025.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.