Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Nova is a ransomware-as-a-service (RaaS) operation that began under the name RALord in March 2025 and rebranded to Nova in April 2025, reportedly after declining a collaboration proposal from the RAWorld/RA World group. Nova runs a double-extortion model: victim data is exfiltrated and files encrypted, with stolen data published on a Tor-based data-leak site (DLS) with countdown timers and proof-of-theft if ransom is not paid. The operation recruits affiliates aggressively with an 85/15 revenue split in the affiliate's favour, and reporting describes a Rust-based cross-platform encryptor supporting Windows, Linux, and VMware ESXi. Reported file extensions across variants include .nova, .RALord and .ralord.
RALord first appeared in late March 2025 (earliest estimated attack ~22 March 2025) and rebranded to Nova in April 2025, standing up an upgraded victim portal with a chat channel and affiliate-registration system. The group grew into a mature RaaS: by mid-2026 its leak site listed roughly 178-180 victims across ~38-44 countries, spanning five continents, with the United States the top target followed by France, Brazil, the Netherlands and Spain. Most-hit sectors include technology, healthcare, manufacturing, education and hospitality. Reported intrusion TTPs (from vendor summaries, not fully corroborated) include phishing, credential theft, abuse of exposed remote services (RDP/VPN), backup destruction and disabling of security tooling; ransomware.live notes a ~66% infostealer correlation among victims, consistent with initial access via stealer logs. There is no official MITRE ATT&CK group ID; Nova RaaS is tracked by Tidal Cyber, RansomLook, ransomware.live and multiple vendors. MENA relevance: REAL leak-site victims, not thin/unverified. Nova's DLS has listed at least one UAE victim (Dubai Air Wing, government/defense, listed 13 Jan 2026) and several Saudi Arabia victims (Rawafid Industrial, energy/water, ~April 2025; Al-Hejailan Group, manufacturing, April 2025; Dosab, wastewater, June 2025). Both RaqibCTI country tags (UAE, Saudi Arabia) are backed by genuine named leak-site postings. Caveat: leak-site listings are unilateral extortion claims and were not independently victim-confirmed here; MENA appears opportunistic within a globally broad, non-region-specific targeting pattern rather than a deliberate MENA focus.
+20 more relationships — see the relationships browser.