nova
Nova (formerly RALord) is a ransomware-as-a-service (RaaS) group that encrypts victims’files and uses double-extortion tactics to pressure organizations into paying for decryption and data non-disclosure.
Nova, formerly RALord, is a financially motivated cybercrime group operating a Ransomware-as-a-Service model and known for double-extortion tactics.
Nova, formerly known as RALord, is a financially motivated cybercrime group operating a Ransomware-as-a-Service (RaaS) model. The group primarily targets sectors such as Technology, Manufacturing, Healthcare, Government & Defense, and Financial Services across the US, Indonesia, Brazil, and various European countries. They employ double-extortion tactics, encrypting files and threatening to leak stolen data to pressure victims into paying for both decryption and non-disclosure. Defenders should focus on robust backup strategies, network segmentation, and enhanced monitoring for data exfiltration attempts.
Nova (formerly RALord) is a ransomware-as-a-service (RaaS) group that encrypts victims’files and uses double-extortion tactics to pressure organizations into paying for decryption and data non-disclosure.
The Nova group employs double-extortion tactics, encrypting files and threatening to leak stolen data to demand payment for both decryption and non-disclosure.
The Nova group primarily targets sectors such as Technology, Manufacturing, Healthcare, Government & Defense, and Financial Services.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.