Orova is a ransomware and data-extortion threat group active in 2026. The group has operated a leak site and publicly claimed numerous victims across the United States, Hong Kong, and Taiwan. Orova has described itself as a startup ransomware-as-a-service operation and as a branch of another group that had previously disappeared, but no higher-confidence attribution to a known parent group or state sponsor is currently available. Observed victimology indicates a preference for small and midsize organizations, including healthcare providers, churches, community associations, professional services firms, technology companies, manufacturers, and financial services organizations. Multiple U.S. medical entities were listed by the group, indicating a notable focus on healthcare. Public reporting also links Orova to attacks on managed service provider infrastructure, with claimed theft of client data from an MSP environment, suggesting potential downstream exposure beyond the directly named victim. Orova's operations are consistent with financially motivated ransomware and extortion activity. The group has claimed both data theft and encryption of victim systems, and has used a leak site with countdown-based publication threats to pressure victims. In at least one reported case, the group claimed to provide decrypted files as proof of compromise during negotiations, and in another case it reportedly stated that stolen data had been deleted and extortion was not pursued. These behaviors indicate a mix of encryption-enabled extortion and data-theft-led coercion rather than a purely destructive objective. Known aliases are limited to Orova. No corroborated sub-groups are currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison to the prior week's ranking; absent from this week's top 10.
Conducting a ransomware attack against Smartsoft, a technology-sector organization in Taiwan.
Conducting a ransomware attack against Ganzhou Xinye Craft Co., Ltd., a manufacturing-sector organization.
Ransomware group newly prominent in the weekly rankings with a substantial number of claimed victims.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.