Skip to main content
Mallory
🇷🇺 RU

RALord

Also known asralord

RALord is an emerging ransomware operation first observed in early 2025. Reporting later references the group as NOVA, indicating a rebrand from RALord to NOVA and identity fluidity across the operation; content also describes Nova as an affiliate program or partnership program associated with the RALord crew. RALord/NOVA is described as a closed group rather than a public ransomware-as-a-service operation in some reporting, though other reporting discusses NOVA RaaS publicly in April 2025 and a NOVA partnership panel. The group has been associated with double extortion activity and with encrypted file extensions ".RALord" and ".ralord," along with ransom notes following the pattern "README-[random_string].txt." The content states that RALord/NOVA emerged or became newly prominent in 2025 and was among the most active ransomware groups targeting MSPs and telecom providers in the first half of 2025. It is also described as launching a concentrated attack on the Middle East, with Asia-Pacific and the Middle East noted as focal regions in related reporting. Victim claims cited in the content include Centrale Nantes, Tomio Ingeniería S.A., IHARA Defensivos Agricolas, Formosa Chang, Pere Claver Group, and Al Hejailan. ASEC reporting also noted a South Korean university listed as a NOVA victim. One reported incident involved a Nova affiliate mistakenly targeting Eriell Group, an oilfield services company headquartered in Uzbekistan with a corporate office in Moscow. According to the content, Nova issued a formal apology, said the responsible affiliate was banned, promised free recovery assistance, claimed no files were encrypted, and pledged not to leak stolen data. This incident is presented in the context of Russian-speaking ransomware crews avoiding Russia and other CIS targets. Known alias: NOVA.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Energy

Where they target

Geographies tied to known operations.

  • 🇺🇿 Uzbekistan
  • 🇷🇺 Russia

Where they're from

Attributed origin per open-source reporting.

  • RU
MITRE ATT&CK

Tradecraft

2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

2 of 15 tactics2 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0010
Exfiltration
1 technique
T1567
Exfiltration Over Web Service
TA0040
Impact
1 technique
T1486
Data Encrypted for Impact
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping2

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.