Unmasking a Nova Ransomware Operator: Following Reused Contact Methods to a Real-World Identity
Brief
TL;DR
Nova did not begin as Nova.
The ransomware-as-a-service operation first emerged publicly in March 2025 under the name RALord , advertising a Rust-based ransomware payload, recruiting affiliates on underground forums, and operating a dedicated data-leak site. Affiliates were reportedly offered approximately 85% of successful ransom payments, while the core operators retained the remaining 15%.
Within weeks, however, the RALord identity began to disappear.
On April 1, 2025, the operators introduced a separate affiliate-facing service carrying the name NOVA RaaS . By the end of the month, the transition was complete: RALord had been rebranded as Nova . Multiple threat-intelligence vendors subsequently treated the two names as the same ransomware lineage.
What initially looked like another newly launched ransomware service subsequently developed into a persistent operation.
