Nova, formerly RALord, is a ransomware-as-a-service operation first observed in March 2025 and rebranded in April 2025. It employs double extortion, stealing data before encrypting files and using a leak site and victim-negotiation infrastructure to pressure organizations into payment. The operation recruits affiliates and provides ransomware payloads for Windows, Linux, and VMware ESXi environments. Reported intrusion activity includes use of compromised VPN or RDP credentials, exploitation of public-facing applications, and spearphishing; affiliates may then perform host and network discovery, credential theft, lateral movement, data exfiltration, backup and security-tool disruption, and ransomware deployment. Nova has claimed victims in healthcare, education, hospitality, IT services, professional services, media, construction, and agriculture. It has been associated with attacks affecting healthcare and patient-data organizations in the Netherlands, although individual victim claims should be independently verified.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The report highlights a surge in malicious activities by Malware-as-a-service (MaaS) operators Sordeal – particularly with their new malware ‘Nova’ – since at least September 2023.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
“Keenadu was also distributed via modified popular apps from unofficial stores and even Google Play, where trojanized smart camera apps with over 300,000 downloads…”
The malware tries to load missing DLLs and creates processes in suspended mode for code injection.
win32snapshot[.]exe (md5: 13639e7f3707d05d90798d21d404eccc), sets the “Circular Kernel Context Logger” registry key value to “0”. As a result, events related to kernel-mode operations, system calls, and other low-level activities will no longer be recorded.
It abuses the inbuilt Windows utility Data Protection Application Programming Interface (DPAPI) to perform data decryption. This API contains a class called ProtectedData, that contains two wrappers: “Protect” and “Unprotect.” The infostealer passes a byte array of the encrypted data to the “Unprotect” wrapper, which subsequently returns a byte array of decrypted data.
The malware targets multiple browsers, including the most used Edge, Chrome and Firefox. Additionally, the malware invokes reg.exe to harvest information related to WinSCP, targeting stored sessions and passwords.
The Chrome configuration is stored in the local AppData directory in a file called “Local State”. This configuration contains an entry called “os_crypt,” which has a sub-entry called “encrypted_key.” The “encrypted_key” is used by Chrome to encrypt saved login data. Below we can see that the malware tries to access that.
The malware uses this open-source utility to capture the screenshot of the target machine.
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation mentioned for an unverified claim that it offers an AI assistant on its leak site.
macOS information stealer distributed through malicious GitHub repositories during the macOS branch of Operation RepoGhost.
Ransomware family/group cited as one of the active actors targeting educational institutions.
국내를 표적으로 삼은 랜섬웨어 그룹 중 하나로 언급된다.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.