NEWS

Nova (RALord) Ransomware Group Confirmed Active with 73

The Nova ransomware group, formerly known as RALord, has been confirmed fully operational with 73 victims across nearly every continent, employing double...

Dylan H.

News Desk

February 17, 2026
3 min read
Nova (RALord) Ransomware Group Confirmed Active with 73

Rebranded and Fully Operational

The Nova ransomware group — formerly known as RALord — has been confirmed fully operational as of February 17, 2026, with 73 confirmed victims spread across nearly every continent. The group combines discipline with opportunism, targeting organizations across diverse sectors.


Group Profile

AttributeDetails
Current NameNova
Former NameRALord
TypeRansomware-as-a-Service (RaaS)
Confirmed Victims73
ReachGlobal — nearly every continent
TacticsDouble extortion (encrypt + exfiltrate + leak)
Latest ActivityFebruary 17, 2026

Double Extortion Model

Nova employs the now-standard double extortion approach:

  1. Encrypt — Lock down victim systems using ransomware payload
  2. Exfiltrate — Steal sensitive data before encryption
  3. Threaten — Demand payment or face public data leak
  4. Leak — Publish stolen data on dedicated leak site if ransom is not paid

Victim Distribution

Nova's targeting shows no particular geographic preference, hitting organizations across:

  • North America — Largest concentration of victims
  • Europe — Western European organizations prominently represented
  • Asia — Growing number of victims in Southeast Asia
  • South America — Brazil and Argentina targeted
  • Africa — Emerging targeting in South Africa and Nigeria
  • Oceania — Australian organizations affected

Evolving Ransomware Landscape

Nova is part of a broader trend where ransomware groups are pivoting tactics as victims increasingly refuse to pay:

TrendDescription
DDoS-as-a-ServiceAdding DDoS pressure on top of encryption and data theft
Insider recruitmentRecruiting employees at target organizations for initial access
Gig worker exploitationUsing freelance workers for money laundering and access brokering
Regulatory pressureReporting victims to regulators to increase pressure to pay
Customer notificationDirectly contacting victim's customers about stolen data

Defensive Recommendations

  1. Immutable backups — Maintain offline, air-gapped backups that cannot be encrypted
  2. Network segmentation — Limit lateral movement paths
  3. EDR/XDR deployment — Detect ransomware behavior before encryption begins
  4. Incident response plan — Have a tested plan specifically for ransomware scenarios
  5. Threat intelligence — Monitor Nova/RALord IOCs and TTPs

With 73 victims in just four months since rebranding, Nova demonstrates that ransomware remains one of the most prolific and profitable cybercrime models in 2026.

Sources