Md5
2 totalbe15f62d14d1cbe2aecce8396f4c62894566f5ba6d1a1db0dd7794ea8d791b3f
RALord is a Rust-based ransomware family and associated ransomware-as-a-service operation first observed in 2025.
Profile source: Mallory opens in a new tabRALord
RALord is a Rust-based ransomware family and associated ransomware-as-a-service operation first observed in 2025. It has also been referenced in later reporting under the Nova branding, reflecting rebranding or affiliate-program evolution within the same criminal ecosystem. The operation uses double extortion, combining file encryption with data theft and leak-site pressure, and has targeted organizations in sectors including healthcare, education, engineering, manufacturing, telecommunications, construction, and tourism, with notable activity affecting victims in Latin America as well as Europe.
RALord is deployed as an operator- or affiliate-enabled encryptor after initial compromise. Reported intrusion paths include attacks against internet-facing perimeter infrastructure and network security products, especially appliances from major enterprise vendors, as well as brute-force activity and exploitation of known vulnerabilities in edge devices, authentication services, and exposed web applications. The group has recruited affiliates in criminal forums and used private messengers for victim and operator communications.
Technically, the malware is written in Rust and performs file and directory enumeration before encrypting data. Reported samples recursively encrypt files within the current working directory tree rather than automatically traversing the entire disk by default. RALord uses a hybrid cryptographic design that includes system-generated randomness, a custom key-wrapping routine, and XChaCha20-Poly1305 for file encryption. It creates ransom notes and appends a distinctive encrypted-file extension. Public reporting also associates the broader Nova branding with negotiated extortion workflows rather than fixed payment instructions.
Observed tradecraft supports both encryption and exfiltration-driven extortion. The operation maintains leak infrastructure on Tor and uses countdown-based pressure tactics to coerce payment. Reporting on Nova-linked incidents indicates theft of sensitive data and threats of public release even where encryption outcomes were disputed. Code-pattern similarities with FunkSec have been noted, suggesting possible code reuse, shared development lineage, or collaboration, although the precise relationship remains unconfirmed.
Implementation flaws have also been reported in early samples, including dependency issues that can cause execution failure on some Windows systems and extension-handling mistakes that may interfere with the malware’s own ransom-note logic. Despite such immaturity indicators, RALord/Nova has been treated as an active profit-motivated criminal ransomware operation rather than a state-linked campaign.
be15f62d14d1cbe2aecce8396f4c62894566f5ba6d1a1db0dd7794ea8d791b3f8E9A6195A769FE7115F087C61D75CF32874C339B3AB0947D07480C9A8A12DA5009151BE6A51F0C8E5B45C57AE244E9C904C5BC74F73306937469D9CEA22541CA69AC162B8D42A20F4C0382AC144.172.95.78054f55ec93aca9bac362b9d91eff36a7ce451e7caba47c0b2e004ba429f9529c79Reported operators
"Nova is a relative newcomer that some security researchers say distributes the RALord ransomware to encrypt files, exfiltrate sensitive data and use double extortion tactics to pressure victims."
Nova is a relative newcomer that some security researchers say distributes the RALord ransomware to encrypt files, exfiltrate sensitive data and use double extortion tactics to pressure victims.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.