Nova (formerly RALord) is a ransomware-as-a-service (RaaS) group that encrypts victims’files and uses double-extortion tactics to pressure organizations into paying for decryption and data non-disclosure. Known victims: 104 1 ransom note(s) on file
Objectives
Executive Summary
Nova, a medium-sophistication criminal threat actor formerly known as RALord, operates as a ransomware-as-a-service (RaaS) group. They primarily engage in double-extortion tactics to encrypt victims' files and extort payments for decryption keys and data non-disclosure. Since first appearing in March 2025, Nova has targeted numerous organizations across various sectors, with over 104 known victims.
Goals & Targeting
Nova's strategic objectives are primarily motivated by financial gain, with a focus on extracting ransoms from victim organizations. Their targeting profile appears to be opportunistic rather than sector-specific, as evidenced by the diverse range of victims across industries. The group likely selects targets based on factors such as organizational size, perceived ability to pay, and vulnerability to phishing or other attack vectors.
Enhanced Description
Nova is a ransomware-as-a-service (RaaS) group that has emerged as a significant threat to global organizations. The group's primary modus operandi involves encrypting victim files and employing double-extortion tactics to maximize payouts. This approach combines the traditional ransomware model with an additional layer of coercion, where victims are threatened with public data exposure unless they pay the demanded cryptocurrency ransoms. Nova's operations have been observed since March 2025, and their attack campaigns have targeted a wide range of industries, including government entities, educational institutions, healthcare providers, and private businesses.
Key Capabilities
Software / Tooling
Campaigns & Victims
Nova's campaigns have exhibited a steady operational tempo since their emergence in late 2025. The group has demonstrated a high volume of activity, with over 104 identified victims across multiple countries. Their attack patterns suggest a reliance on phishing emails and malicious payloads, likely leveraging existing frameworks or tools for distribution. Notable past operations include attacks against educational institutions, government agencies, and private sector companies.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low-Medium confidence due to limited specificity on attack vectors and TTPs. Further analysis of the linked campaigns and associated tools would enhance understanding of Nova's operational capabilities.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
84
Campaigns
415
IOCs
0
Observed Data
0
Tactics