This profile covers the NOVA RANSOMWARE operation (RaaS), which emerged as RALord in March 2025 and rebranded to Nova in April 2025. It is explicitly NOT the unrelated 'Nova Stealer' (a NovaSentinel/SnakeStealer-family infostealer sold on Telegram), and not the Babuk-derived generic 'Nova' label some vendors use loosely. Note: 'Nova' is a heavily reused name; the RALord->Nova cluster is the double-extortion RaaS profiled here. Some reporting speculates Nova's encryptor may reuse leaked Babuk source, but this lineage is unconfirmed. Operator nationality is unknown.
Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
Double-extortion model: data staged and transferred to operator Tor/leak infrastructure before encryption, with volumes posted on the DLS (Halcyon; SonicWall; Cyjax DLS analysis) - transport specifics not published, mapped at parent level
Halcyon and Xcitium report Nova affiliates gain entry with compromised/reused credentials (often infostealer-sourced) against exposed RDP/VPN lacking MFA
Exposed RDP/VPN endpoints are the reported entry surface for Nova affiliates (Halcyon threat-group profile; Xcitium Jan-2026)
Regional co-occurrence · associated techniques
Honesty note
Regional co-occurrence is association, not prediction. These techniques appeared alongside Nova's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
protect · 7 techniques
Advanced Anti-Phishing T1566partialApp GovernanceT1562significantAnti-SpoofingT1566significantDefender for Cloud AppsT1133partialDefender for Cloud AppsT1567partialConditional AccessT1078minimalIdentity Secure ScoreT1078minimalMultifactor AuthenticationT1078minimalMultifactor AuthenticationT1566partialPrivileged Identity ManagementT1078minimalPassword PolicyT1078significantPassword ProtectionT1078partialRole Based Access ControlT1078minimalRole Based Access ControlT1562minimalAntimalwareT1566significantAnti-PhishingT1566significantAntiSpamT1566significantAudit SolutionsT1078partialAudit SolutionsT1562partialInformation ProtectionT1070significantInformation ProtectionT1070.001significantInformation ProtectionT1567significant
detect · 8 techniques
Advanced Anti-Phishing T1566partialApp GovernanceT1078significantApp GovernanceT1562significantApp GovernanceT1566significantAdvanced Threat HuntingT1078significantAdvanced Threat HuntingT1562significantAdvanced Threat HuntingT1566significantAdvanced Threat HuntingT1567significantDefender for Cloud AppsT1078partialDefender for Cloud AppsT1133partialDefender for Cloud AppsT1486partialDefender for Cloud AppsT1567partialMicrosoft Defender for IdentityT1133minimalLateral Movements
respond · 4 techniques
Advanced Anti-Phishing T1566partialAutomated Investigation and ResponseT1078significantAutomated Investigation and ResponseT1566significantAutomated Investigation and ResponseT1567significantIncident ResponseT1078minimalIncident ResponseT1562minimalIncident ResponseT1566minimalQuarantine PoliciesT1566significantSafe AttachmentsT1566significantATT&CK Simulation TrainingT1566partialZero Hour Auto PurgeT1566significantConditional AccessT1078minimal
Countermeasures · D3FEND
Defensive techniques that counter Nova's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.