Analyzing Nova Ransomware Rust-Based Evasion and Encryption
Score: 8/10

Analyzing Nova Ransomware Rust-Based Evasion and Encryption

Nova is a Rust-based Ransomware-as-a-Service that employs extensive Microsoft Defender evasion, process termination of security tools, and hybrid encryption to target multiple sectors globally.

Executive Summary

Nova is an active Ransomware-as-a-Service (RaaS) operation that rebranded from RALord in April 2025. Written in Rust, the malware demonstrates a high degree of technical sophistication in its defense evasion strategy, specifically targeting Microsoft Defender and various EDR/AV solutions. The operation follows a double-extortion model, with a leak site already listing approximately 180 victims across 38 countries as of mid-2026.

The attack chain begins with environmental discovery and anti-analysis checks, followed by multi-layered attempts to disable security controls via PowerShell, WMI, and registry modifications. The final stage involves inhibiting recovery by deleting Volume Shadow Copies and deploying a hybrid cryptographic scheme (XChaCha20-Poly1305 and RSA-2048). The opportunistic nature of Nova suggests it remains a significant threat to technology, manufacturing, and healthcare sectors worldwide.

Key Details

Threat Name

Nova Ransomware

Affects

—

Adversary

Nova Other Adversaries and Aliases: RAWorld

Malware/Tools

Nova, Babuk, SysJoker, REvil, LockBit, CatB

Report Score

8out of 10
Quality Score
Good
IOC Quality6
TTP Details9
Detection Guidance7
Enterprise Relevance9
Clarity & Structure9
Technical Depth8

Sources