Tox
1 total8E9A6195A769FE7115F087C61D75CF32874C339B3AB0947D07480C9A8A12DA5009151BE6A51F
Nova, formerly known as RALord, is a ransomware-as-a-service operation first observed in March 2025 and rebranded in April 2025.
Profile source: Mallory opens in a new tabNova
Nova, formerly known as RALord, is a ransomware-as-a-service operation first observed in March 2025 and rebranded in April 2025. It employs double extortion, exfiltrating data and encrypting victim files to pressure victims through leak-site publication and negotiation infrastructure. Nova has claimed victims across healthcare, education, hospitality, IT services, professional services, construction, agriculture, and other sectors, including organizations in Europe and South Korea. The operation recruits affiliates and provides ransomware payloads for Windows, Linux, and VMware ESXi environments. Reported affiliate tradecraft includes initial access using compromised remote-access credentials, exploitation of public-facing applications, and spearphishing; post-compromise activity includes host and network discovery, credential theft, privilege escalation, remote lateral movement, backup and shadow-copy removal, security-process termination, data exfiltration, and encryption. Nova has used persistence mechanisms including scheduled tasks, remote-access tooling, and Windows autorun configuration.
8E9A6195A769FE7115F087C61D75CF32874C339B3AB0947D07480C9A8A12DA5009151BE6A51F054f55ec93aca9bac362b9d91eff36a7ce451e7caba47c0b2e004ba429f9529c79Reported operators
The report highlights a surge in malicious activities by Malware-as-a-service (MaaS) operators Sordeal – particularly with their new malware ‘Nova’ – since at least September 2023.
MITRE ATT&CK
Reporting
Ransomware activity intensified in 2026 as the criminal ecosystem expanded to 146 active groups by midyear, with 61 new groups emerging and public victim counts rising sharply across multiple regions and sectors. Black Kite reported 7,551 victims globally, a 55.1% year-over-year increase in Europe during the first four months of the year, and continued dominance by a small number of operators despite broader fragmentation. Qilin remained the leading ransomware-as-a-service operation across much of the market, benefiting from the decline of rivals such as LockBit and ALPHV, while researchers said attackers frequently gained initial access by exploiting critical vulnerabilities with CVSS >= 9 and, in some cases, through phishing and supply-chain compromise. At the same time, The Gentlemen emerged as one of the fastest-growing threats, especially against higher education. Comparitech counted 104 ransomware attacks against the global education sector in the first half of 2026, with attacks increasingly concentrated on colleges and universities and the United States recording the most confirmed victims. ESET said The Gentlemen equipped affiliates with the GentleKiller framework, a bring-your-own-vulnerable-driver toolkit designed to disable endpoint defenses before encryption, targeting more than 400 processes across roughly 48 security products. The group was also linked to steep growth in university attacks, including a case at Mount Royal University involving a $1.9 million ransom demand, alleged theft of more than 10TB of data, and destructive deletion of drives.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.