Attribution
Unattributed. No public reporting links Orova to a named, previously tracked ransomware operation, affiliate program, or nation-state. It is treated as an independent, emerging double-extortion brand that surfaced in 2026. Any attribution beyond 'unknown operator' would be speculation.
Motivation
Financial (data-theft extortion / ransomware)
Attribution confidence
medium
Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Why it mattersRansomware actor, medium confidence, documented targeting Egypt (Healthcare sector).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.