Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors ralord

Description

RALord is a ransomware group identified in March 2025 operating within the NOVA RaaS platform, targeting healthcare, education, hospitality, and IT sectors across multiple continents, using a Rust-based payload with an 85/15 affiliate revenue split; it later rebranded as "Nova." Known victims: 19 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 2 weeks ago

Executive Summary

The RALord ransomware group, operating within the NOVA RaaS platform, has been targeting various sectors across multiple continents, using a Rust-based payload with an 85/15 affiliate revenue split. The group has been active since March 2025, with 19 known victims and has since rebranded as 'Nova'. Their primary motivation is organizational gain, with goals of ransomware and financial gain.

Goals & Targeting

The RALord ransomware group's strategic objectives appear to be focused on achieving financial gain through ransomware attacks. They target various sectors, including healthcare, education, hospitality, and IT, across multiple continents. The group's typical victims are likely organizations with valuable data and a willingness to pay a ransom to restore access to their systems. The group's targeting profile suggests that they are opportunistic and willing to adapt to different environments, making them a significant threat to organizations across various sectors.

Enhanced Description

The targeting of various sectors across multiple continents suggests that the group has a broad range of interests and is willing to adapt to different environments. The fact that they have 19 known victims and have been active for several months indicates a moderate level of success and a potential for continued activity. As the group continues to evolve, it is likely that their tactics, techniques, and procedures (TTPs) will become more sophisticated, making them a significant threat to organizations across various sectors.

Key Capabilities

  • Ransomware development and deployment
  • Custom malware development
  • Network exploitation
  • Data encryption
  • Affiliate revenue management

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1110
T1021

Software / Tooling

Rust-based ransomware payload
Custom malware
Ransomware-as-a-service (RaaS) platform

Campaigns & Victims

The RALord ransomware group's campaign patterns suggest a moderate level of operational tempo, with 19 known victims and activity across multiple continents. The group's use of a Rust-based payload and affiliate revenue model indicates a high level of organization and coordination. Notable past operations include the targeting of healthcare, education, hospitality, and IT sectors, with a focus on achieving ransomware and financial gain.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting
  • Ransomware payloads with 85/15 affiliate revenue split

Recommended Actions

  • Implement robust network security measures, including firewalls and intrusion detection systems
  • Conduct regular security awareness training for employees
  • Use anti-virus software and ensure it is up-to-date
  • Implement a backup and disaster recovery plan
  • Monitor for suspicious network activity and respond quickly to potential security incidents

Suggested Tags

Ransomware
Criminal
RaaS
Organizational gain
Financial gain

Confidence Assessment

The available data on the RALord ransomware group is moderate, with some information gaps existing. The group's rebranding to Nova and the lack of detailed information on their internal structure and operations reduce the confidence level. However, the known victims and the group's use of a Rust-based payload and affiliate revenue model provide some insight into their capabilities and motivations.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

3

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Mar 22, 2025
Last Seen
Apr 27, 2025
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.