Skip to content

— Nova

Threat-actor battle card · maintained from public sources · last updated 2026-06-23 · also known as RALord

CategoryRansomware
AttributionUnknown (CIS/DPRK/China exclusion suggests Russian-speaking ecosystem; unconfirmed)
First seen2025-05
StatusActive
Rank#3
Recent victims · last ~9d15
All-time victims155
Primary targetsTechnology, Manufacturing, Healthcare, Education, Business Services

Overview

Nova (formerly RALord, rebranded approximately April–May 2025) is a ransomware-as-a-service (RaaS) operation using double-extortion — exfiltrate, then encrypt. As of June 2026, ransomware.live tracks 147 claimed victims across 42 countries since first appearing on the threat landscape in May 2025. Nova debuted in the May 2026 top-10 by monthly victim volume (#9 in this tracker). The United States is the primary target (22 victims), followed by France (10) and Brazil (10).

Top targeted sectors: Technology (29), Manufacturing (24), Healthcare (18), Education (17), Business Services (12).

Nova publicly pledges not to target schools or nonprofit organisations. It maintains an explicit CIS-country exclusion (Commonwealth of Independent States — Russia, Ukraine, Kazakhstan, and other former Soviet republics), along with DPRK and China — an exclusion pattern consistent with, though not uniquely indicative of, a Russian-speaking operation. The exclusion is enforced via affiliate agreement: in June 2026, Nova issued a formal public apology after an affiliate violated the rule by encrypting Eriell Group (oilfield services, Uzbekistan); the affiliate was banned and Nova pledged free recovery assistance and no data leak.

Tradecraft

  • Double-extortion: exfiltrate before encryption; data published on DLS if ransom deadline expires.
  • RaaS model: central operators manage the platform, affiliates execute intrusions.
  • CIS, DPRK, and China excluded per affiliate contract (enforced with documented affiliate bans).
  • Schools and nonprofits excluded per stated policy.
  • No confirmed initial-access vector published by authoritative sources — leave .
  • Encryption method, lateral-movement tools, and ransom demand structure: (unconfirmed in authoritative sources).

Notable victims

  • Trevi — construction/engineering/Italy — seen 2026-06-09 — ransomware.live DLS
  • SUNASS — government/water regulator/Peru — seen 2026-06-17 — ransomware.live DLS
  • Lockers IT — IT services/Bangladesh — seen 2026-06-21 — ransomware.live DLS
  • Eriell Group — oilfield services/Uzbekistan — CIS-rule violation; affiliate banned; no leak pledged — 2026-05-26 — Daily Security Review · CiphersSecurity

Assessment

Nova is a mid-tier RaaS platform with broad global reach and consistent growth since its May 2025 debut. Its willingness to publicly discipline affiliates for rules violations signals operational maturity and a desire to maintain affiliate trust and plausible deniability. The CIS/DPRK/China exclusion and Russian-language forum activity are suggestive of a Russian-speaking operation, but attribution is unconfirmed. At 147 victims across 42 countries in roughly 13 months of operation, the growth trajectory warrants inclusion in the top-10 watch list; escalation to Tier-1 status depends on June 2026 monthly reporting confirming the count above current top-8 actors.

Sources

🗂️ Attacks & victims

All disclosed victims attributed to this actor, newest first.

June 2026

Jun 24 lpgroup Nova Ransomware · unknown · N/A 🟥 Claimed (leak-site) · — Unknown (CIS/DPRK/China exclusion suggests Russian-speaking ecosystem; unconfirmed) · #3 active · 155 total · disclosed 1d ago · Sources: ransomware.live
Jun 24 alejandria Nova Ransomware · unknown · N/A 🟥 Claimed (leak-site) · — Unknown (CIS/DPRK/China exclusion suggests Russian-speaking ecosystem; unconfirmed) · #3 active · 155 total · disclosed 1d ago · Sources: ransomware.live
Jun 24 transvill Nova Ransomware · unknown · N/A 🟥 Claimed (leak-site) · — Unknown (CIS/DPRK/China exclusion suggests Russian-speaking ecosystem; unconfirmed) · #3 active · 155 total · disclosed 1d ago · Sources: ransomware.live
Jun 23 cloudquantum Nova Ransomware · unknown · — 🟥 Claimed (leak-site) · — Unknown (CIS/DPRK/China exclusion suggests Russian-speaking ecosystem; unconfirmed) · #3 active · 155 total · disclosed 2d ago · Sources: ransomware.live DLS
Jun 23 FTL-Fast Transit Line Nova Ransomware · unknown · — 🟥 Claimed (leak-site) · — Unknown (CIS/DPRK/China exclusion suggests Russian-speaking ecosystem; unconfirmed) · #3 active · 155 total · disclosed 2d ago · Sources: ransomware.live DLS
Jun 21 Lockers IT Nova Ransomware · IT services · Bangladesh 🟥 Claimed (leak-site) · — Unknown (CIS/DPRK/China exclusion suggests Russian-speaking ecosystem; unconfirmed) · #3 active · 155 total · disclosed 4d ago · Sources: ransomware.live DLS
Jun 21 Nhà Thành Phố Nova Ransomware · unknown · Vietnam 🟥 Claimed (leak-site) · — Unknown (CIS/DPRK/China exclusion suggests Russian-speaking ecosystem; unconfirmed) · #3 active · 155 total · disclosed 4d ago · Sources: ransomware.live DLS
Jun 20 Dosab Nova Ransomware · unknown · Saudi Arabia 🟥 Claimed (leak-site) · — Unknown (CIS/DPRK/China exclusion suggests Russian-speaking ecosystem; unconfirmed) · #3 active · 155 total · disclosed 5d ago · Sources: ransomware.live DLS
Jun 20 Hosab Nova Ransomware · unknown · — 🟥 Claimed (leak-site) · — Unknown (CIS/DPRK/China exclusion suggests Russian-speaking ecosystem; unconfirmed) · #3 active · 155 total · disclosed 5d ago · Sources: ransomware.live DLS
Jun 20 MIT HJERTE Nova Ransomware · unknown · Denmark 🟥 Claimed (leak-site) · — Unknown (CIS/DPRK/China exclusion suggests Russian-speaking ecosystem; unconfirmed) · #3 active · 155 total · disclosed 5d ago · Sources: ransomware.live DLS
Jun 20 One Believing Interiors Nova Ransomware · unknown · — 🟥 Claimed (leak-site) · — Unknown (CIS/DPRK/China exclusion suggests Russian-speaking ecosystem; unconfirmed) · #3 active · 155 total · disclosed 5d ago · Sources: ransomware.live DLS
Jun 19 Desert Micro Nova Ransomware · unknown · — 🟥 Claimed (leak-site) · — Unknown (CIS/DPRK/China exclusion suggests Russian-speaking ecosystem; unconfirmed) · #3 active · 155 total · disclosed 6d ago · Sources: ransomware.live DLS
Jun 17 SUNASS Nova Ransomware · government · water regulator/Peru 🟥 Claimed (leak-site) · — Unknown (CIS/DPRK/China exclusion suggests Russian-speaking ecosystem; unconfirmed) · #3 active · 155 total · disclosed 8d ago · Sources: ransomware.live DLS
Jun 16 Kedah Nova Ransomware · unknown · Malaysia 🟥 Claimed (leak-site) · — Unknown (CIS/DPRK/China exclusion suggests Russian-speaking ecosystem; unconfirmed) · #3 active · 155 total · disclosed 9d ago · Sources: ransomware.live DLS
Jun 09 Trevi Nova Ransomware · construction-engineering · Italy 🟥 Claimed (leak-site) · — Unknown (CIS/DPRK/China exclusion suggests Russian-speaking ecosystem; unconfirmed) · #3 active · 155 total · disclosed 16d ago · Sources: ransomware.live DLS

← All threat actors · Full victim database →