Orova is a ransomware and data-extortion group first publicly observed in 2026. It operates a leak site and has claimed numerous victims across the United States, Hong Kong, and Taiwan, with reported targeting spanning health care, technology, manufacturing, construction and professional services, real estate, financial services, and civil-society organizations. The group emerged among highly active ransomware claimants in August 2026, when it published 35 victim claims in a single week. Orova has described itself as a startup ransomware-as-a-service operation and as a branch of an earlier group that ceased operating; the predecessor group is not publicly identified. In an intrusion affecting a U.S. cardiology practice, Orova claimed to have exfiltrated extensive patient and business data and encrypted some servers. Available evidence from the claimed data indicated exposure of protected health information and personally identifiable information. The operation uses leak-site publication threats alongside ransomware activity, consistent with double-extortion operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed ransomware attack against Fu Sheng Industrial Co., Ltd, a manufacturing company.
Conducted a ransomware attack against ASYS Corporation, a Taiwan-based semiconductor-technology services and industrial IoT organization.
Claimed breach of Cardiology Associates of Port Huron and publication of personally identifiable information and protected health information on its leak site; the article title attributes a claim of 150,000 cardiology patient records to the group.
Alleged data-extortion operation against a Michigan cardiology practice. The group claims to have stolen 256,382 files totaling approximately 496 GB, including patient PII, protected health information, insurance records, claims/remittance data, and medical imaging, while also encrypting some servers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.