Sordeal Group, also known as Sordeal and sordeal_group, is a French-speaking malware-as-a-service operator active since early 2023. It has developed, marketed, and supported the Nova/Nova Sentinel, MALICORD, and NOVABLIGHT information-stealer ecosystem through messaging platforms, code-hosting services, and criminal marketplaces. The group offers time-limited build access, payload-generation services, victim-data dashboards, and promotional free keys, enabling use by other threat actors. Sordeal malware has been distributed using deceptive software and video-game installer lures. Nova and NOVABLIGHT collect browser credentials and other protected browser data, Discord session tokens, stored remote-access client credentials, system profiling data, screenshots, clipboard contents, Wi-Fi credentials, webcam captures, and files selected using sensitive-data keywords. The malware can decrypt data protected by Windows DPAPI and has targeted Chromium-based browsers, Firefox, Discord, and cryptocurrency-wallet applications. NOVABLIGHT is a modular Node.js/Electron stealer that can inject malicious code into Electron applications, including communications, VPN, email, and cryptocurrency-wallet software. Its wallet-focused functionality can capture passphrases and replace cryptocurrency or payment addresses in the clipboard, supporting cryptocurrency theft. The malware exfiltrates collected data through operator-controlled panels, messaging-platform webhooks and bots, and third-party file-transfer services. Sordeal tooling incorporates defense-evasion and disruptive post-compromise features, including layered JavaScript obfuscation, anti-debugging and virtual-machine checks, remotely maintained analysis-environment blocklists, and termination of security-analysis processes. It can attempt to weaken endpoint protections and logging, establish startup persistence, inject code into processes, interfere with network connectivity and recovery functions, and remove volume shadow copies. The operation has continued to develop its malware and application-injection capabilities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
50 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Developer/operator behind NOVABLIGHT, a NodeJS-based Malware-as-a-Service infostealer sold via Telegram, Discord, and online storefronts. The group is also linked in the content to Nova Sentinel and MALICORD, and supports payload building, dashboards, and exfiltration infrastructure for customers.
French-language-proficient malware-as-a-service operator responsible for developing and selling the NodeJS/Electron-based NOVABLIGHT information stealer. The group distributes licenses and payload-building capability via Telegram and Discord, supports stolen-data dashboards, and enables credential theft, crypto-address clipboard substitution, Electron application injection, system sabotage, and multi-channel exfiltration.
MaaS operators developing and distributing the Nova infostealer, using free key giveaways and public repositories to expand adoption. Their malware focuses on persistence, credential theft, browser and application data harvesting, Discord injection, and emerging crypto-wallet targeting, while employing anti-forensic and defense-evasion techniques.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.