RALord is a ransomware group identified in March 2025 operating within the NOVA RaaS platform, targeting healthcare, education, hospitality, and IT sectors across multiple continents, using a Rust-based payload with an 85/15 affiliate revenue split; it later rebranded as "Nova." Known victims: 19 1 ransom note(s) on file
Objectives
Executive Summary
The RALord ransomware group, operating within the NOVA RaaS platform, has been targeting various sectors across multiple continents, using a Rust-based payload with an 85/15 affiliate revenue split. The group has been active since March 2025, with 19 known victims and has since rebranded as 'Nova'. Their primary motivation is organizational gain, with goals of ransomware and financial gain.
Goals & Targeting
The RALord ransomware group's strategic objectives appear to be focused on achieving financial gain through ransomware attacks. They target various sectors, including healthcare, education, hospitality, and IT, across multiple continents. The group's typical victims are likely organizations with valuable data and a willingness to pay a ransom to restore access to their systems. The group's targeting profile suggests that they are opportunistic and willing to adapt to different environments, making them a significant threat to organizations across various sectors.
Enhanced Description
The targeting of various sectors across multiple continents suggests that the group has a broad range of interests and is willing to adapt to different environments. The fact that they have 19 known victims and have been active for several months indicates a moderate level of success and a potential for continued activity. As the group continues to evolve, it is likely that their tactics, techniques, and procedures (TTPs) will become more sophisticated, making them a significant threat to organizations across various sectors.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The RALord ransomware group's campaign patterns suggest a moderate level of operational tempo, with 19 known victims and activity across multiple continents. The group's use of a Rust-based payload and affiliate revenue model indicates a high level of organization and coordination. Notable past operations include the targeting of healthcare, education, hospitality, and IT sectors, with a focus on achieving ransomware and financial gain.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data on the RALord ransomware group is moderate, with some information gaps existing. The group's rebranding to Nova and the lack of detailed information on their internal structure and operations reduce the confidence level. However, the known victims and the group's use of a Rust-based payload and affiliate revenue model provide some insight into their capabilities and motivations.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
3
IOCs
0
Observed Data
0
Tactics