NO

nova

Known ransomware group ACTIVE
Currently active

Nova (formerly RALord) is a ransomware-as-a-service (RaaS) group that encrypts victims’files and uses double-extortion tactics to pressure organizations into paying for decryption and data non-disclosure.

7

Total Claims

1

Critical

Records Claimed

2

Industries Hit

Active span: May 17, 2026 – Jun 6, 2026 · 7 organizations targeted

Currently active
Activity 5.6 Severity 3.6 Sectors 3.7 Tooling 0.0

Actor Threat Profile

Activity Timeline

Peak: May 2026 (5)
May 2026
LessMore
Jun 2026

Share this profile

Shareable intel card for nova

Top Targeted Industries

Education 6
Healthcare 1

Tradecraft & Infrastructure

0

Documented tools

0 / 0

MITRE tactics / techniques

9

Known leak sites

Full intelligence profile on ransomware.live →

Claims by nova

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.