Ransomware
RALordNova RaaSRALord/Nova
Attribution
This profile covers the NOVA RANSOMWARE operation (RaaS), which emerged as RALord in March 2025 and rebranded to Nova in April 2025. It is explicitly NOT the unrelated 'Nova Stealer' (a NovaSentinel/SnakeStealer-family infostealer sold on Telegram), and not the Babuk-derived generic 'Nova' label some vendors use loosely. Note: 'Nova' is a heavily reused name; the RALord->Nova cluster is the double-extortion RaaS profiled here. Some reporting speculates Nova's encryptor may reuse leaked Babuk source, but this lineage is unconfirmed. Operator nationality is unknown.
Motivation
Financial (double-extortion ransomware-as-a-service)
Attribution confidence
medium
MENA targeting
UAE, Saudi Arabia
Sectors
Transportation, manufacturing, energy/utilities
Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Why it mattersRansomware actor, medium confidence, documented targeting UAE, Saudi Arabia (Transportation, manufacturing, energy/utilities sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.