← Back to feed
Breaches & RansomwareEmerging1 sourceSep 25, 2026 · 18:35via Malware.news

Unmasking a Nova Ransomware Operator: Following Reused Contact Methods to a Real-World Identity

Brief

TL;DR

Nova did not begin as Nova.

The ransomware-as-a-service operation first emerged publicly in March 2025 under the name RALord , advertising a Rust-based ransomware payload, recruiting affiliates on underground forums, and operating a dedicated data-leak site. Affiliates were reportedly offered approximately 85% of successful ransom payments, while the core operators retained the remaining 15%.

Within weeks, however, the RALord identity began to disappear.

On April 1, 2025, the operators introduced a separate affiliate-facing service carrying the name NOVA RaaS . By the end of the month, the transition was complete: RALord had been rebranded as Nova . Multiple threat-intelligence vendors subsequently treated the two names as the same ransomware lineage.

What initially looked like another newly launched ransomware service subsequently developed into a persistent operation.

Read more on Malware.news→