Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

Nova (formerly RALord) is a ransomware-as-a-service (RaaS) group that encrypts victims’files and uses double-extortion tactics to pressure organizations into paying for decryption and data non-disclosure. Known victims: 104 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Nova, a medium-sophistication criminal threat actor formerly known as RALord, operates as a ransomware-as-a-service (RaaS) group. They primarily engage in double-extortion tactics to encrypt victims' files and extort payments for decryption keys and data non-disclosure. Since first appearing in March 2025, Nova has targeted numerous organizations across various sectors, with over 104 known victims.

Goals & Targeting

Nova's strategic objectives are primarily motivated by financial gain, with a focus on extracting ransoms from victim organizations. Their targeting profile appears to be opportunistic rather than sector-specific, as evidenced by the diverse range of victims across industries. The group likely selects targets based on factors such as organizational size, perceived ability to pay, and vulnerability to phishing or other attack vectors.

Enhanced Description

Nova is a ransomware-as-a-service (RaaS) group that has emerged as a significant threat to global organizations. The group's primary modus operandi involves encrypting victim files and employing double-extortion tactics to maximize payouts. This approach combines the traditional ransomware model with an additional layer of coercion, where victims are threatened with public data exposure unless they pay the demanded cryptocurrency ransoms. Nova's operations have been observed since March 2025, and their attack campaigns have targeted a wide range of industries, including government entities, educational institutions, healthcare providers, and private businesses.

Key Capabilities

  • Ransomware-as-a-Service (RaaS) operations
  • Double extortion tactics
  • Encryption of victim files
  • Social engineering via phishing campaigns

Software / Tooling

Custom ransomware

Campaigns & Victims

Nova's campaigns have exhibited a steady operational tempo since their emergence in late 2025. The group has demonstrated a high volume of activity, with over 104 identified victims across multiple countries. Their attack patterns suggest a reliance on phishing emails and malicious payloads, likely leveraging existing frameworks or tools for distribution. Notable past operations include attacks against educational institutions, government agencies, and private sector companies.

IOC Patterns

  • Ransomware deployment targeting organizational data
  • Double extortion email communication from threat actors
  • Encrypted files with specific extension patterns

Recommended Actions

  • Implement robust phishing detection mechanisms to mitigate potential payloads.
  • Enhance network monitoring for suspicious lateral movement and encryption activities.
  • Regularly back up critical data and store backups offline to prevent ransomware-induced data loss.
  • Conduct employee training on identifying social engineering attempts.

Suggested Tags

ransomware
double extortion
financial-gain

Confidence Assessment

Low-Medium confidence due to limited specificity on attack vectors and TTPs. Further analysis of the linked campaigns and associated tools would enhance understanding of Nova's operational capabilities.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 17 URL 3

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

84

Campaigns

415

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure
ransomware
double extortion
financial-gain

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Mar 22, 2025
Last Seen
Jul 25, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.