Tox
1 total8E9A6195A769FE7115F087C61D75CF32874C339B3AB0947D07480C9A8A12DA5009151BE6A51F
Nova, formerly known as RALord, is a ransomware-as-a-service operation first observed in 2025.
Profile source: Mallory opens in a new tabNova
Nova, formerly known as RALord, is a ransomware-as-a-service operation first observed in 2025. It is associated with double-extortion activity in which affiliates steal data and encrypt victim systems, then pressure organizations through leak-site publication and ransom negotiations. Reporting links the ransomware to Babuk-derived code and describes cross-platform payloads written in Rust for Windows, Linux, and VMware ESXi environments. Nova has been observed targeting organizations across multiple sectors, including healthcare, education, professional services, hospitality, IT services, media, construction, and agriculture, with victim claims spanning multiple regions.
Novaโs intrusion model includes several common enterprise compromise paths. Initial access has been associated with compromised VPN or RDP credentials, credential stuffing and password reuse, purchases from initial access brokers, exploitation of public-facing applications, and spearphishing disguised as legitimate business communications. After access, affiliates conduct system and network discovery, harvest credentials, move laterally through administrative protocols and remote management mechanisms, and target backup infrastructure to inhibit recovery. Reported tradecraft includes use of PowerShell and command interpreters, credential dumping from LSASS, theft of browser and credential-store data, use of legitimate remote administration tools, and propagation to virtualized environments including ESXi.
Defense evasion and impact techniques attributed to Nova include terminating security and backup processes, deleting shadow copies, modifying boot settings to force Safe Mode with Networking before encryption, and using multiple payload variants and extensions. The ransomware is reported to encrypt files with symmetric encryption protected by public-key cryptography, while exfiltrating large volumes of data before deployment of the locker. Nova also operates leak and negotiation infrastructure to support affiliate operations and victim communications.
Nova has been publicly described as aggressively recruiting affiliates on criminal forums and offering favorable revenue sharing and low-cost locker access. The operation has been tied to attacks and claims affecting healthcare and education institutions, including incidents in the Netherlands and South Korea, and has appeared in ransomware victim tallies during 2025 and 2026. Public reporting also notes an operational link between Nova and the broader RALord network, including a rebranding from RALord to Nova shortly after initial emergence.
8E9A6195A769FE7115F087C61D75CF32874C339B3AB0947D07480C9A8A12DA5009151BE6A51F054f55ec93aca9bac362b9d91eff36a7ce451e7caba47c0b2e004ba429f9529c79MITRE ATT&CK
Reporting
Ransomware activity intensified in 2026 as the criminal ecosystem expanded to 146 active groups by midyear, with 61 new groups emerging and public victim counts rising sharply across multiple regions and sectors. Black Kite reported 7,551 victims globally, a 55.1% year-over-year increase in Europe during the first four months of the year, and continued dominance by a small number of operators despite broader fragmentation. Qilin remained the leading ransomware-as-a-service operation across much of the market, benefiting from the decline of rivals such as LockBit and ALPHV, while researchers said attackers frequently gained initial access by exploiting critical vulnerabilities with CVSS >= 9 and, in some cases, through phishing and supply-chain compromise. At the same time, The Gentlemen emerged as one of the fastest-growing threats, especially against higher education. Comparitech counted 104 ransomware attacks against the global education sector in the first half of 2026, with attacks increasingly concentrated on colleges and universities and the United States recording the most confirmed victims. ESET said The Gentlemen equipped affiliates with the GentleKiller framework, a bring-your-own-vulnerable-driver toolkit designed to disable endpoint defenses before encryption, targeting more than 400 processes across roughly 48 security products. The group was also linked to steep growth in university attacks, including a case at Mount Royal University involving a $1.9 million ransom demand, alleged theft of more than 10TB of data, and destructive deletion of drives.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.