Skip to content

RALord

RALord is a Rust-based ransomware family and associated ransomware-as-a-service operation first observed in 2025.

Profile source: Mallory opens in a new tab

RALord

Family profile

RALord is a Rust-based ransomware family and associated ransomware-as-a-service operation first observed in 2025. It has also been referenced in later reporting under the Nova branding, reflecting rebranding or affiliate-program evolution within the same criminal ecosystem. The operation uses double extortion, combining file encryption with data theft and leak-site pressure, and has targeted organizations in sectors including healthcare, education, engineering, manufacturing, telecommunications, construction, and tourism, with notable activity affecting victims in Latin America as well as Europe.

RALord is deployed as an operator- or affiliate-enabled encryptor after initial compromise. Reported intrusion paths include attacks against internet-facing perimeter infrastructure and network security products, especially appliances from major enterprise vendors, as well as brute-force activity and exploitation of known vulnerabilities in edge devices, authentication services, and exposed web applications. The group has recruited affiliates in criminal forums and used private messengers for victim and operator communications.

Technically, the malware is written in Rust and performs file and directory enumeration before encrypting data. Reported samples recursively encrypt files within the current working directory tree rather than automatically traversing the entire disk by default. RALord uses a hybrid cryptographic design that includes system-generated randomness, a custom key-wrapping routine, and XChaCha20-Poly1305 for file encryption. It creates ransom notes and appends a distinctive encrypted-file extension. Public reporting also associates the broader Nova branding with negotiated extortion workflows rather than fixed payment instructions.

Observed tradecraft supports both encryption and exfiltration-driven extortion. The operation maintains leak infrastructure on Tor and uses countdown-based pressure tactics to coerce payment. Reporting on Nova-linked incidents indicates theft of sensitive data and threats of public release even where encryption outcomes were disputed. Code-pattern similarities with FunkSec have been noted, suggesting possible code reuse, shared development lineage, or collaboration, although the precise relationship remains unconfirmed.

Implementation flaws have also been reported in early samples, including dependency issues that can cause execution failure on some Windows systems and extension-handling mistakes that may interfere with the malware’s own ransom-note logic. Despite such immaturity indicators, RALord/Nova has been treated as an active profit-motivated criminal ransomware operation rather than a state-linked campaign.

Capabilities

  • Brute Force
  • Exfiltration
  • Extortion
  • Reconnaissance

Operational record

6
Indicators
1
YARA rules
1
Ransom notes
4
Leak sites
1 available

Published indicators

Md5

2 total
  • be15f62d14d1cbe2aecce8396f4c6289
  • 4566f5ba6d1a1db0dd7794ea8d791b3f

Tox

2 total
  • 8E9A6195A769FE7115F087C61D75CF32874C339B3AB0947D07480C9A8A12DA5009151BE6A51F
  • 0C8E5B45C57AE244E9C904C5BC74F73306937469D9CEA22541CA69AC162B8D42A20F4C0382AC

Ip

1 total
  • 144.172.95.78

Session

1 total
  • 054f55ec93aca9bac362b9d91eff36a7ce451e7caba47c0b2e004ba429f9529c79

Reported operators

Threat actors

2 named in public reporting
Nova

"Nova is a relative newcomer that some security researchers say distributes the RALord ransomware to encrypt files, exfiltrate sensitive data and use double extortion tactics to pressure victims."

RA Group

Nova is a relative newcomer that some security researchers say distributes the RALord ransomware to encrypt files, exfiltrate sensitive data and use double extortion tactics to pressure victims.

MITRE ATT&CK

RALord in ATT&CK

4 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.