nova
Known ransomware group ACTIVE Currently active
Nova (formerly RALord) is a ransomware-as-a-service (RaaS) group that encrypts victims’files and uses double-extortion tactics to pressure organizations into paying for decryption and data non-disclosure.
7
Total Claims
1
Critical
—
Records Claimed
2
Industries Hit
Active span: May 17, 2026 – Jun 6, 2026 · 7 organizations targeted
Currently active
Actor Threat Profile
Activity Timeline
Peak: May 2026 (5)May 2026
LessMore
Jun 2026Top Targeted Industries
Education 6
Healthcare 1
Tradecraft & Infrastructure
0
Documented tools
0 / 0
MITRE tactics / techniques
9
Known leak sites
Targeted Organizations
Claims by nova
Low
Ransomware Claim: Universitas Nasional
Universitas Nasional
nova
Ransomware Education
Jun 7, 2026 Critical
Ransomware Claim: Aspire hospital
Aspire hospital
nova
Ransomware Healthcare
Jun 6, 2026 Low
Ransomware Claim: Daegu University AI Department
Daegu University AI Department
nova
Ransomware Education
May 30, 2026 Low
Ransomware Claim: My English House academy
My English House academy
nova
Ransomware Education
May 28, 2026 Low
Ransomware Claim: University of Valencia
University of Valencia
nova
Ransomware Education
May 24, 2026 Low
Ransomware Claim: Wysza Szkoa Biznesu National Louis University
Wysza Szkoa Biznesu National Louis University
nova
Ransomware Education
May 20, 2026 Low
Ransomware Claim: Don Bosco Technical Institute of Makati
Don Bosco Technical Institute of Makati
nova
Ransomware Education
May 18, 2026