RALord, later rebranded as Nova or NOVA, is an emerging ransomware operation first observed in early 2025. Reporting consistently links Nova to the same underlying actor set or network as RALord, with the rebrand reflecting the fluid identity practices common in the ransomware ecosystem. Nova has been described both as a ransomware crew and as an affiliate program associated with the RALord operation. Known aliases include RALord, RaLord, Nova, and NOVA. The group has been active in double-extortion operations, combining data theft with threats of public exposure and, in some reporting, encryption. It has been associated with recruitment of affiliates and the launch of a partnership panel under the Nova branding, indicating movement toward a ransomware-as-a-service or affiliate-based operating model. Some reporting, however, characterizes the operation as relatively closed rather than a broadly open public RaaS program. High-confidence reporting supports at minimum that the group pursued affiliate recruitment and operated a partnership structure under the Nova name. Victimology indicates broad opportunistic targeting across multiple sectors, with particular attention in 2025 to managed service providers, telecommunications providers, and organizations in the Middle East. The operation has also appeared in broader ransomware victim-claim tracking throughout 2025 and 2026, indicating sustained activity rather than a short-lived campaign. It has been identified among active groups affecting small and medium-sized organizations, consistent with wider ransomware trends. Operationally, RALord/Nova fits the contemporary ransomware model of leak-site-driven extortion, affiliate enablement, and rapid brand adaptation. The group has been discussed alongside other newly prominent 2025 ransomware actors as part of a fragmented ecosystem in which smaller crews quickly adopt established playbooks. Public reporting also notes the operation’s identity fluidity, with the Nova rebrand used to continue or expand activity under a new label. A notable incident involved a Nova affiliate mistakenly targeting Eriell Group, a CIS-linked oilfield services company. Following notification from the victim, Nova publicly apologized, stated that the responsible affiliate had been banned, and claimed that encryption did not occur and stolen data would not be leaked. This incident is significant because many Russian-speaking ransomware operations avoid targeting Russia and other CIS entities, whether for self-preservation, criminal norms, or safe-harbor considerations. The response suggests Nova operated within that broader ecosystem logic. Overall, RALord/Nova is best understood as a 2025-era ransomware actor that evolved from the RALord name into the Nova brand, used affiliate or partnership structures, engaged in double extortion, and maintained recurring activity across multiple regions and sectors, with notable emphasis on MSP and telecom targeting and expansion toward the Middle East.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group listed among the most active groups in week 29 of 2026 with 7 claimed victims.
Ransomware group maintaining a stable weekly presence with 10 claimed victims.
Named ransomware network associated with Nova; discussed in the context of enforcing internal rules after an accidental strike on a CIS-linked oilfield services company.
Ransomware crew whose affiliate program accidentally infected a CIS-linked company, then apologized, promised recovery assistance, and said it would not leak stolen data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.