Ransomware Series: Nova Ransomware Encryption Activity via CLI Subcommands and R
Detects the execution of Nova ransomware (formerly RALord) by monitoring for its specific modular command-line interface arguments, which include file encryption commands, ransom note deployment, and specific ransom note filenames. The rule monitors process creation events for strings like 'encrypt-all', 'encrypt-path', 'readme-add', '--workers', and the presence of the 'README_NOVA.me' ransom note or unique file extensions associated with its encryption activity.
Sigma

