Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Orova is an emerging financially motivated ransomware and data-extortion group first observed in mid-2026. It runs a Tor-hosted data leak site with countdown-based victim postings and a separate Tor chat portal plus a Tox ID for negotiations. It practices double extortion: exfiltrating data, encrypting some servers, providing sample files/decryption proof, and threatening publication if unpaid. Public trackers recorded roughly 36-45 named victims by late August 2026.
Orova appears in ransomware-tracking feeds beginning around May 2026, with the earliest recorded victim attack dated 2026-05-21 and the group's tracker 'first seen' listed as early-to-mid 2026 (ransomware.live cites July 7, 2026 as its discovery date; victim attack dates run earlier). Activity accelerated through August 2026, including a batch of new Taiwan/Hong Kong postings on 2026-08-29 to 08-31 and news coverage of five Hong Kong firms. Reported victimology is concentrated in the United States (largest share, ~24), Hong Kong (~10), and Taiwan (~8), with single victims in Brazil, Japan, and Egypt; healthcare and financial services are the most-hit sectors. Vendor mappings (SOCRadar) describe TTPs including Valid Accounts and autostart persistence, network sniffing for discovery, remote services / alternate authentication material for lateral movement, web-protocol C2, and Data Encrypted for Impact with inhibited recovery and disabled security tools; VPN/edge exploitation is cited as a likely entry vector. Reporting quality is moderate: the group is tracked by multiple independent aggregators (ransomware.live, SOCRadar, WatchGuard, Ransomwhere) and one mainstream news outlet, but there is no in-depth malware analysis, sample hash set, or attribution study, and victim counts differ across sources as pages update. Claims are self-reported leak-site postings and should be treated with caution until independently verified. MENA relevance: REAL but minimal. Ransomware.live records one Egypt-based leak-site victim, ADG Healthcare, with an attack date of 2026-05-21. This is a single, self-reported extortion listing rather than an independently confirmed breach, and Orova shows no broader MENA focus (its concentration is US and East Asia). The Egypt country tag is therefore justified by one genuine leak-site victim, but Orova is not a MENA-oriented actor.