β Nova¶
Threat-actor battle card Β· maintained from public sources Β· last updated 2026-09-12 Β· also known as RALord
Overview¶
Nova (formerly RALord, rebranded approximately AprilβMay 2025) is a ransomware-as-a-service (RaaS) operation using double-extortion β exfiltrate, then encrypt. As of late July 2026, ransomware.live tracks ~180 claimed victims across 38β44 countries since first appearing in May 2025. Nova holds the #9 position in this tracker. The United States remains the primary target; Indonesia has emerged as a concentrated cluster in MayβJuly 2026 (Badan Pangan Nasional, Balai Besar POM di Bandung, Dephub/maritime ministry, KOPKARLA telecom cooperative β four Indonesian government/state-linked entities in three months). Monthly cadence: 23 victims (May 2026), 28 (June 2026).
Top targeted sectors: Technology, Manufacturing, Healthcare, Education, Business Services, Government, Transportation, Telecom. The July 2026 victim mix includes Indonesian government agencies, Italian MSPs, Hong Kong managed services, Vietnam cloud infrastructure, and Argentinian universities β consistent with broad global opportunistic targeting with an emerging Southeast Asian government focus.
Nova publicly pledges not to target schools or nonprofit organisations. It maintains an explicit CIS-country exclusion (Commonwealth of Independent States β Russia, Ukraine, Kazakhstan, and other former Soviet republics), along with DPRK and China β an exclusion pattern consistent with, though not uniquely indicative of, a Russian-speaking operation. The exclusion is enforced via affiliate agreement: in June 2026, Nova issued a formal public apology after an affiliate violated the rule by encrypting Eriell Group (oilfield services, Uzbekistan); the affiliate was banned and Nova pledged free recovery assistance and no data leak. In 2025, Nova declined an approach from Chinese ransomware collective RAWorld to join forces and rebranded from RALord around the same time (Red Hot Cyber interview, 2025).
Tradecraft¶
- Double-extortion: exfiltrate before encryption; data published on DLS if ransom deadline expires.
- RaaS model: central operators manage the platform, affiliates execute intrusions (90%+ affiliate revenue share market-competitive).
- CIS, DPRK, and China excluded per affiliate contract (enforced with documented affiliate bans).
- Schools and nonprofits excluded per stated policy.
- Encryptor: Rust-based 64-bit Windows PE (721 KB); cross-platform: Windows, Linux, VMware ESXi. PE compile timestamp February 3, 2026 β active development confirmed in 2026. (Source: AttackIQ, July 31, 2026.)
- Encryption scheme: Hybrid XChaCha20-Poly1305 + RSA-2048. File extension:
.xgWLckNV. Ransom note:README_NOVA.me(dropped per directory). Registry artifact:HKLM\SOFTWARE\NovaRansom. - Defender evasion: PowerShell + registry modifications to disable Microsoft Defender features; service manipulation; process termination β described as multi-layered.
- Anti-analysis:
tasklistenumeration against hardcoded process list of RE/debugging/monitoring tools; terminates on detection. - Recovery inhibition: VSS deletion via both
vssadminand WMI (dual-method). - C2: Tor/onion infrastructure.
- Codebase: Multiple aggregators (ReliaQuest, SOCRadar) report Babuk source-code lineage from the 2021 leak; the Rust implementation and XChaCha20 scheme are distinct from classic Babuk (HC-128 + EC). The connection likely refers to operator/affiliate lineage rather than direct code inheritance β treat as unconfirmed.
- Initial access vector and lateral movement tools:
β(unconfirmed in authoritative sources). - Behavioral note (2025 precedent): Nova violated its own no-second-payment pledge in the Eurofins subsidiary (NMDL) case, demanding 11 BTC (~$1.3M) after an initial ransom was paid (July 2025). The Northwave analysis documented this as a rules violation, not standard practice; no repeat in 2026 confirmed.
Notable victims¶
July 2026 (new): - Dephub / kemenhub.go.id β Directorate of Shipping & Maritime Affairs/government/Indonesia β 483 employees, 926 users, 87 third-party creds, 166 external attack surface points exfiltrated; π₯ DLS claim β seen 2026-07-19 β DeXpose Β· SOCRadar - KOPKARLA / Koperasi Karyawan PT Aplikanusa Lintasarta β telecom cooperative/Indonesia; π₯ DLS claim β seen 2026-07-20 β DeXpose - SistNet (Sistemi Tre s.r.l.) β MSP/IT services/Italy β 200 GB exfiltrated; 13-14 day data release deadline set; π₯ DLS claim β seen 2026-07-25 β DeXpose - Digital Edge β managed services provider/Hong Kong β client data at risk; π₯ DLS claim β seen 2026-07-24 β DeXpose - VNSO / CΓ΄ng nghα» VNSO β cloud/VPS/CDN provider/Vietnam; π₯ DLS claim β seen 2026-07-22 β SOCRadar Β· HookPhish - Marpatech β instrumentation/control/industrial mining/Peru; π₯ DLS claim β seen 2026-07-22 β DeXpose - Universidad Nacional de Mar del Plata β education/Argentina; π₯ DLS claim β seen 2026-07-20 β DeXpose - TΓ¨rra Aventura β tourism/Portugal; π₯ DLS claim β seen 2026-07-21 β HookPhish - Integrated Marketing Services β commercial printing/US (Liverpool, NY); π₯ DLS claim β seen 2026-07-17 β DeXpose - Hynet β IT services/unknown; π₯ DLS claim β seen 2026-07-10 β SOCRadar - KPMG Netherlands β professional services/Netherlands β 500 GB claimed; 10-day deadline; KPMG denied any compromise of managed systems; π₯ unverified β seen 2026-01-23 β Cybernews Β· SC World
June 2026: - NSW Rural Fire Service (rfs.nsw.gov.au) β emergency services/government/Australia β 300 GB exfiltrated; RFS confirmed breach June 24, 2026; Nova DLS claim June 26 β seen 2026-06-26 β Cyber Daily - Kedah State Government β government/Malaysia β π₯ unverified β seen 2026-06-16 β DeXpose Β· ransomware.live - FTL-Fast Transit Line β transportation-logistics/Belgium β seen 2026-06-23 β ransomware.live DLS - VSL Marine Technology β marine engineering/India β seen 2026-06-26 β ransomware.live DLS - Dosab β industrial zone authority/Turkey β seen 2026-06-20 β RedPacket Security Β· ransomware.live DLS - Transvill SRL β transportation-logistics/Peru β seen 2026-06-24 β ransomware.live DLS - Eriell Group β oilfield services/Uzbekistan β CIS-rule violation; affiliate banned; no leak pledged β 2026-05-26 β Daily Security Review
Assessment¶
Nova is a mid-tier RaaS platform with broad global reach and consistent growth since its May 2025 debut. At ~180 victims across 38β44 countries in 14 months, it holds a stable #9 position. The AttackIQ July 2026 encryptor analysis confirms operational maturity: the Rust implementation with XChaCha20-Poly1305 + RSA-2048 hybrid, multi-layered Defender evasion, dual VSS deletion, and cross-platform ESXi support puts Nova above the "commodity script-kiddie" tier. The CIS/DPRK/China exclusion remains consistently enforced; the 2025 RAWorld rejection is consistent with a Russian-speaking operator not wanting to share infrastructure or revenue with a Chinese collective.
July 2026 added a new geographic cluster: Indonesia (four government/state-linked victims in one month β maritime ministry, food regulator, telecom cooperative), which may indicate an affiliate with specific regional access or targeting knowledge. This is the clearest sectoral/geographic signal in Nova's 14-month history. The 2025 NMDL double-ransom violation (Northwave documented) is on record as a behavioral precedent β Nova's stated rules are real but not absolute.
September 2026 update: no named-victim reporting or vendor analysis has surfaced since the July 31 AttackIQ encryptor writeup β this card's most recent authoritative technical source. Aggregator cumulative-victim counts diverge sharply across trackers this period (from the mid-40s to 180+, depending on methodology and dedup rules) and are not treated as more reliable than the group's own prior confirmed activity; one aggregator flags a roughly 39% month-over-month drop in claimed activity, unconfirmed by any named source. Treat Nova as active but currently under-reported rather than assign a new trend either way; rank/l3m/ytd left unchanged pending the next Tier-1 leaderboard refresh.
Sources¶
- ransomware.live β Nova group statistics
- AttackIQ β Analyzing Nova Ransomware: A Rust-Based Encryptor with Multi-Layered Microsoft Defender Evasion Techniques (2026-07-31)
- SOCRadar β VNSO Nova Ransomware 2026
- DeXpose β Nova Ransomware Attack on Dephub Indonesia
- SonicWall β Nova RaaS: The Ransomware That 'Spares' Schools and Nonprofits
- Xcitium ThreatLabs β From RALord to Nova: How This RaaS Gang Is Wreaking Havoc Worldwide
- Red Hot Cyber β RHC Interviews NOVA Ransomware (2025)
- Northwave Cybersecurity β A New Phase in Ransomware? Criminals Break Their Own Rules
- CYJAX β ARaaStocracy: RALord ransomware emerges with new DLS (2025)
- Daily Security Review β Nova Ransomware Apologizes for CIS Rule Violation
- Ransom-DB β Nova / RALord Ransomware Group Analysis 2026
ποΈ Attacks & victims¶
All disclosed victims attributed to this actor, newest first.
July 2026
June 2026