Executive Summary
Nova is an active Ransomware-as-a-Service (RaaS) operation that rebranded from RALord in April 2025. Written in Rust, the malware demonstrates a high degree of technical sophistication in its defense evasion strategy, specifically targeting Microsoft Defender and various EDR/AV solutions. The operation follows a double-extortion model, with a leak site already listing approximately 180 victims across 38 countries as of mid-2026.
The attack chain begins with environmental discovery and anti-analysis checks, followed by multi-layered attempts to disable security controls via PowerShell, WMI, and registry modifications. The final stage involves inhibiting recovery by deleting Volume Shadow Copies and deploying a hybrid cryptographic scheme (XChaCha20-Poly1305 and RSA-2048). The opportunistic nature of Nova suggests it remains a significant threat to technology, manufacturing, and healthcare sectors worldwide.
