Skip to content

β€” Nova

Threat-actor battle card Β· maintained from public sources Β· last updated 2026-09-12 Β· also known as RALord

CategoryRansomware
AttributionUnknown (CIS/DPRK/China exclusion suggests Russian-speaking ecosystem; Babuk lineage reported by aggregators, unconfirmed; declined collaboration with Chinese group RAWorld in 2025)
First seen2025-05
StatusActive
Rank#9
Primary targetsTechnology, Manufacturing, Healthcare, Education, Business Services, Government, Transportation, Telecom

Overview

Nova (formerly RALord, rebranded approximately April–May 2025) is a ransomware-as-a-service (RaaS) operation using double-extortion β€” exfiltrate, then encrypt. As of late July 2026, ransomware.live tracks ~180 claimed victims across 38–44 countries since first appearing in May 2025. Nova holds the #9 position in this tracker. The United States remains the primary target; Indonesia has emerged as a concentrated cluster in May–July 2026 (Badan Pangan Nasional, Balai Besar POM di Bandung, Dephub/maritime ministry, KOPKARLA telecom cooperative β€” four Indonesian government/state-linked entities in three months). Monthly cadence: 23 victims (May 2026), 28 (June 2026).

Top targeted sectors: Technology, Manufacturing, Healthcare, Education, Business Services, Government, Transportation, Telecom. The July 2026 victim mix includes Indonesian government agencies, Italian MSPs, Hong Kong managed services, Vietnam cloud infrastructure, and Argentinian universities β€” consistent with broad global opportunistic targeting with an emerging Southeast Asian government focus.

Nova publicly pledges not to target schools or nonprofit organisations. It maintains an explicit CIS-country exclusion (Commonwealth of Independent States β€” Russia, Ukraine, Kazakhstan, and other former Soviet republics), along with DPRK and China β€” an exclusion pattern consistent with, though not uniquely indicative of, a Russian-speaking operation. The exclusion is enforced via affiliate agreement: in June 2026, Nova issued a formal public apology after an affiliate violated the rule by encrypting Eriell Group (oilfield services, Uzbekistan); the affiliate was banned and Nova pledged free recovery assistance and no data leak. In 2025, Nova declined an approach from Chinese ransomware collective RAWorld to join forces and rebranded from RALord around the same time (Red Hot Cyber interview, 2025).

Tradecraft

  • Double-extortion: exfiltrate before encryption; data published on DLS if ransom deadline expires.
  • RaaS model: central operators manage the platform, affiliates execute intrusions (90%+ affiliate revenue share market-competitive).
  • CIS, DPRK, and China excluded per affiliate contract (enforced with documented affiliate bans).
  • Schools and nonprofits excluded per stated policy.
  • Encryptor: Rust-based 64-bit Windows PE (721 KB); cross-platform: Windows, Linux, VMware ESXi. PE compile timestamp February 3, 2026 β€” active development confirmed in 2026. (Source: AttackIQ, July 31, 2026.)
  • Encryption scheme: Hybrid XChaCha20-Poly1305 + RSA-2048. File extension: .xgWLckNV. Ransom note: README_NOVA.me (dropped per directory). Registry artifact: HKLM\SOFTWARE\NovaRansom.
  • Defender evasion: PowerShell + registry modifications to disable Microsoft Defender features; service manipulation; process termination β€” described as multi-layered.
  • Anti-analysis: tasklist enumeration against hardcoded process list of RE/debugging/monitoring tools; terminates on detection.
  • Recovery inhibition: VSS deletion via both vssadmin and WMI (dual-method).
  • C2: Tor/onion infrastructure.
  • Codebase: Multiple aggregators (ReliaQuest, SOCRadar) report Babuk source-code lineage from the 2021 leak; the Rust implementation and XChaCha20 scheme are distinct from classic Babuk (HC-128 + EC). The connection likely refers to operator/affiliate lineage rather than direct code inheritance β€” treat as unconfirmed.
  • Initial access vector and lateral movement tools: β€” (unconfirmed in authoritative sources).
  • Behavioral note (2025 precedent): Nova violated its own no-second-payment pledge in the Eurofins subsidiary (NMDL) case, demanding 11 BTC (~$1.3M) after an initial ransom was paid (July 2025). The Northwave analysis documented this as a rules violation, not standard practice; no repeat in 2026 confirmed.

Notable victims

July 2026 (new): - Dephub / kemenhub.go.id β€” Directorate of Shipping & Maritime Affairs/government/Indonesia β€” 483 employees, 926 users, 87 third-party creds, 166 external attack surface points exfiltrated; πŸŸ₯ DLS claim β€” seen 2026-07-19 β€” DeXpose Β· SOCRadar - KOPKARLA / Koperasi Karyawan PT Aplikanusa Lintasarta β€” telecom cooperative/Indonesia; πŸŸ₯ DLS claim β€” seen 2026-07-20 β€” DeXpose - SistNet (Sistemi Tre s.r.l.) β€” MSP/IT services/Italy β€” 200 GB exfiltrated; 13-14 day data release deadline set; πŸŸ₯ DLS claim β€” seen 2026-07-25 β€” DeXpose - Digital Edge β€” managed services provider/Hong Kong β€” client data at risk; πŸŸ₯ DLS claim β€” seen 2026-07-24 β€” DeXpose - VNSO / CΓ΄ng nghệ VNSO β€” cloud/VPS/CDN provider/Vietnam; πŸŸ₯ DLS claim β€” seen 2026-07-22 β€” SOCRadar Β· HookPhish - Marpatech β€” instrumentation/control/industrial mining/Peru; πŸŸ₯ DLS claim β€” seen 2026-07-22 β€” DeXpose - Universidad Nacional de Mar del Plata β€” education/Argentina; πŸŸ₯ DLS claim β€” seen 2026-07-20 β€” DeXpose - TΓ¨rra Aventura β€” tourism/Portugal; πŸŸ₯ DLS claim β€” seen 2026-07-21 β€” HookPhish - Integrated Marketing Services β€” commercial printing/US (Liverpool, NY); πŸŸ₯ DLS claim β€” seen 2026-07-17 β€” DeXpose - Hynet β€” IT services/unknown; πŸŸ₯ DLS claim β€” seen 2026-07-10 β€” SOCRadar - KPMG Netherlands β€” professional services/Netherlands β€” 500 GB claimed; 10-day deadline; KPMG denied any compromise of managed systems; πŸŸ₯ unverified β€” seen 2026-01-23 β€” Cybernews Β· SC World

June 2026: - NSW Rural Fire Service (rfs.nsw.gov.au) β€” emergency services/government/Australia β€” 300 GB exfiltrated; RFS confirmed breach June 24, 2026; Nova DLS claim June 26 β€” seen 2026-06-26 β€” Cyber Daily - Kedah State Government β€” government/Malaysia β€” πŸŸ₯ unverified β€” seen 2026-06-16 β€” DeXpose Β· ransomware.live - FTL-Fast Transit Line β€” transportation-logistics/Belgium β€” seen 2026-06-23 β€” ransomware.live DLS - VSL Marine Technology β€” marine engineering/India β€” seen 2026-06-26 β€” ransomware.live DLS - Dosab β€” industrial zone authority/Turkey β€” seen 2026-06-20 β€” RedPacket Security Β· ransomware.live DLS - Transvill SRL β€” transportation-logistics/Peru β€” seen 2026-06-24 β€” ransomware.live DLS - Eriell Group β€” oilfield services/Uzbekistan β€” CIS-rule violation; affiliate banned; no leak pledged β€” 2026-05-26 β€” Daily Security Review

Assessment

Nova is a mid-tier RaaS platform with broad global reach and consistent growth since its May 2025 debut. At ~180 victims across 38–44 countries in 14 months, it holds a stable #9 position. The AttackIQ July 2026 encryptor analysis confirms operational maturity: the Rust implementation with XChaCha20-Poly1305 + RSA-2048 hybrid, multi-layered Defender evasion, dual VSS deletion, and cross-platform ESXi support puts Nova above the "commodity script-kiddie" tier. The CIS/DPRK/China exclusion remains consistently enforced; the 2025 RAWorld rejection is consistent with a Russian-speaking operator not wanting to share infrastructure or revenue with a Chinese collective.

July 2026 added a new geographic cluster: Indonesia (four government/state-linked victims in one month β€” maritime ministry, food regulator, telecom cooperative), which may indicate an affiliate with specific regional access or targeting knowledge. This is the clearest sectoral/geographic signal in Nova's 14-month history. The 2025 NMDL double-ransom violation (Northwave documented) is on record as a behavioral precedent β€” Nova's stated rules are real but not absolute.

September 2026 update: no named-victim reporting or vendor analysis has surfaced since the July 31 AttackIQ encryptor writeup β€” this card's most recent authoritative technical source. Aggregator cumulative-victim counts diverge sharply across trackers this period (from the mid-40s to 180+, depending on methodology and dedup rules) and are not treated as more reliable than the group's own prior confirmed activity; one aggregator flags a roughly 39% month-over-month drop in claimed activity, unconfirmed by any named source. Treat Nova as active but currently under-reported rather than assign a new trend either way; rank/l3m/ytd left unchanged pending the next Tier-1 leaderboard refresh.

Sources

πŸ—‚οΈ Attacks & victims

All disclosed victims attributed to this actor, newest first.

July 2026

Jul 25 SistNet Nova Ransomware Β· IT Services Β· Unknown DLS posting July 25 2026 by Nova group. IT services firm. Country and data scope unconfirmed. Β· Sources: https://www.ransomware.live/
Jul 19 MER-AL Nova Ransomware Β· manufacturing (automotive components) Β· Turkey Nova DLS posting July 19; data claimed exfiltrated; unverified β€” no public statement from MER-AL Β· Sources: https://www.ransomware.live
Jul 19 Dephub Nova Ransomware Β· government (transportation/ports authority) Β· Indonesia Nova DLS posting July 19; Indonesian government transportation and ports authority entity; data claimed exfiltrated; unverified β€” no public statement from Dephub Β· Sources: https://www.ransomware.live

June 2026

Jun 26 NSW Rural Fire Service Nova Ransomware Β· government Β· emergency services/Australia New South Wales Rural Fire Service; Nova DLS claim June 26, 2026; 300 GB claimed; RFS confirmed the breach June 24 but stated emergency operations were unaffected; no evidence of operational impact Β· https://www.cyberdaily.au/security/13817-exclusive-nova-ransomware-group-takes-responsibility-for-nsw-rfs-hack Β· https://www.ransomware.live/group/nova Β· Sources: [Cyber Daily] Β· [ransomware.live]
Jun 26 VSL Marine Technology Pvt. Ltd. Nova Ransomware Β· marine engineering Β· 3D scanning/India marine technology and underwater survey services provider; Nova DLS claim June 26, 2026; data scope and impact unconfirmed; πŸŸ₯ unverified Β· https://www.dexpose.io/nova-ransomware-attack-targets-vsl-marine-technology-pvt-ltd/ Β· https://www.ransomware.live/group/nova Β· Sources: [DeXpose] Β· [ransomware.live]
Jun 24 Alexandria Nova Ransomware Β· telecommunications Β· unknown region teleinfrastructure platform; DLS claim June 24, 2026; data scope unconfirmed Β· https://www.ransomware.live/ Β· Sources: [ransomware.live]
Jun 24 LP Group Nova Ransomware Β· construction Β· real estate/unknown region completed ~1 million sq metres of projects; DLS claim June 24, 2026; data scope unconfirmed Β· https://www.ransomware.live/ Β· Sources: [ransomware.live]
Jun 24 Transvill SRL Nova Ransomware Β· transportation-logistics Β· Peru national and international road transport and cargo logistics; DLS claim June 24, 2026; data scope and impact unconfirmed Β· https://www.ransomware.live/ Β· https://www.redpacketsecurity.com/nova-ransomware-victim-transvill-com-pe/ Β· Sources: [ransomware.live] Β· [RedPacket Security]
Jun 23 FTL-Fast Transit Line Nova Ransomware Β· transportation-logistics Β· Belgium Belgian logistics company; DLS claim June 23, 2026; data scope and impact unconfirmed Β· https://www.dexpose.io/nova-ransomware-targets-ftl-fast-transit-line/ Β· https://www.ransomware.live/group/nova Β· Sources: [DeXpose] Β· [ransomware.live]
Jun 21 Lockers IT Nova Ransomware Β· IT services Β· Bangladesh Sources: ransomware.live DLS
Jun 20 One Believing Interiors Nova Ransomware Β· interior design Β· US interior design studio specializing in built spaces including National Gallery projects; DLS claim June 20, 2026; data scope and impact unconfirmed Β· https://www.hookphish.com/blog/ransomware-group-nova-hits-one-believing-interiors/ Β· https://www.ransomware.live/id/T25lIEJlbGlldmluZyBJbnRlcmlvcnNAbm92YQ== Β· Sources: [HookPhish] Β· [ransomware.live]
Jun 20 MIT HJERTE Nova Ransomware Β· sector unknown Β· Denmark DLS claim June 20, 2026; data scope and impact unconfirmed Β· https://www.hookphish.com/blog/ransomware-group-nova-hits-mit-hjerte/ Β· https://www.ransomware.live/group/nova Β· Sources: [HookPhish] Β· [ransomware.live]
Jun 20 Dosab Nova Ransomware Β· industrial zone Β· Turkey organized industrial zone operator in Bursa, Turkey; Nova DLS claim June 20, 2026; data scope and impact unconfirmed Β· https://www.redpacketsecurity.com/nova-ransomware-victim-dosab/ Β· https://www.ransomware.live/group/nova Β· Sources: [RedPacket Security] Β· [ransomware.live]
Jun 17 SUNASS Nova Ransomware Β· government Β· water regulator/Peru Sources: ransomware.live DLS
Jun 16 Kedah State Government Nova Ransomware Β· government Β· Malaysia official state government portal providing public services for Kedah, Malaysia; Nova DLS claim June 16, 2026; estimated attack date June 16; data scope and impact unconfirmed Β· https://www.dexpose.io/nova-ransomware-group-targets-kedah-state-government/ Β· https://www.ransomware.live/id/S2VkYWhAbm92YQ== Β· Sources: [DeXpose] Β· [ransomware.live]
Jun 09 Trevi Nova Ransomware Β· construction-engineering Β· Italy Sources: ransomware.live DLS

← All threat actors Β· Full victim database β†’