Ransomware Group intelligence
Nova
ActiveTrack Nova with 221 published victims and 11 known leak locations in a single intelligence view.
Overview
Nova is tracked by Breach House as a ransomware group with 221 published victims.
United States is currently the most targeted country in this dataset.
11 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (11)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 11 | Onion service | Up checked 1h ago | novak6fgohb7m6nm52lgpaaquntawixqsnpcptomwaiiz4mfydztatqd.onion |
| Leak location 10 | Onion service | Down checked 1h ago | novaf2pxzvb7xzkunlctqfuifatnp6pnhctvrqakizqflzr3rvqbnqid.onion |
| Leak location 9 | Onion service | Down checked 1h ago | novav75eqkjoxct7xuhhwnjw5uaaxvznhtbykq6zal5x7tfevxzjyqyd.onion |
| Leak location 4 | Onion service | Down checked 1h ago | novatd4577pzlvdyy42slydhrhru7fpcflbbxlajcmbfrgzyeis6d3id.onion |
| Leak location 8 | Onion service | Down checked 1h ago | novadmrkp4vbk2padk5t6pbxolndceuc7hrcq4mjaoyed6nxsqiuzyyd.onion |
| Leak location 7 | Onion service | Down checked 1h ago | novag4k2te3mstt2xq5irywlpaw6edgkpiwgg4t2q7eecisj2qqtvbid.onion |
| Leak location 1 | Onion service | Down checked 1h ago | novavdivko2zvtrvtllnq45lxhba2rfzp76qigb4nrliklem5au7czqd.onion |
| Leak location 6 | Onion service | Down checked 1h ago | pifk3xu3vad6cuxsjll4qjomyaaaoyvnyqppro75pazadzctrrvpdnyd.onion |
| Leak location 5 | Onion service | Down checked 1h ago | novaxtychr6ohlc4zr5its73p6i7unpuhpwoodtzrg2y4w4seytatlid.onion |
| Leak location 3 | Onion service | Down checked 1h ago | novaoddh3vxylxqpsfdjprliknbzgbkv6nkazpzu3cvykrgpyzuywryd.onion |
| Leak location 2 | Onion service | Down checked 1h ago | leak7y2247fj7dbb35rpfyxuyaqtwbshiwxp6h35ttzlhrxmhvi4fead.onion |
Top Activity Sectors (17)
- Communication / Marketing 24
- IT 23
- Not identified 20
- Manufacturing / Engineering 17
- Healthcare / Pharma 15
- Public Sector 14
- Education 14
- Services 11
- Transportation / Travel / Logistics 9
- Construction / Real Estate 9
- Telecommunications 6
- Finance / Legal / Insurance 5
- Retail / E-commerce 5
- Hospitality / Food & Beverage / Tourism 2
- NGOs / Associations 2
- Energy 1
- Agriculture / Food 1
Typical Attacks (9)
▼MITRE ATT&CK does not currently catalogue Nova, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: nova executes malicious commands via PowerShell scripts to stage payloads and manipulate system processes.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: nova modifies registry run keys to ensure malware execution upon system reboot for persistence.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: nova disables antivirus tools and security software to prevent detection and hinder incident response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.016 Junk Code Insertion Stealth
What they do: nova embeds junk code into its binaries to evade static analysis and signature-based detection.
What that means: Adversaries may use junk code / dead code to obfuscate a malware’s functionality.
-
T1070.004 File Deletion Stealth
What they do: nova deletes Volume Shadow Copies and backup directories via command-line utilities to eliminate recovery options.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1135 Network Share Discovery Discovery
What they do: nova scans network shares using native tools to identify victim files and expand its foothold.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: nova leverages SMB/Windows Admin Shares for lateral movement across networked systems within the victim environment.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: nova encrypts victim files using symmetric encryption to maximize disruption and ransom demand leverage.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: nova executes system recovery inhibition commands to prevent automatic restoration from backups or snapshots.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README-NOVA.me
----------------------------------------------------------------------------- Ransom ----------------------------------------------------------------------------- -> Hello , without any problems , if you see this Readme its mean you under controll by Nova ransomware , Data stolen and will be leaked if didn't contact us in 48 hours - encrypted files have ext .[victim_name]NV DON'T TOUCH IT -> Data from your network will be leaked in 10 days , take action and get in touch please --- make sure that the best way to less the time for you is contacted us to recover and decrypt your secret data and stop leak operation ----------------- >>> what we will provide and help with ? -> we will provide advanced decryptor easy for use and we will return every file or data we delete or stole from your Network -> we will give you link to download data stolen from your network as plus recover -> we provide report to how fix your network , and how we gain access and bypass your security, and some advice to up your security ----------------- >>> contact us here (use tor Browser to access chat): download tor from torproject.org ---------------- Chat system (TOR) join link : http://c43mpmijbb7rrvb3gc2w2hli7haeyrr2jlsl6xguveysfxwkt2iayjqd.onion/chat put any username to join ---------------- - our session messanger ID (Add ons , please use chat in tor to contact , contact in session if you can't access chat) : 054f55ec93aca9bac362b9d91eff36a7ce451e7caba47c0b2e004ba429f9529c79 (https://getsession.org) - also you can use qtox ID : 8E9A6195A769FE7115F087C61D75CF32874C339B3AB0947D07480C9A8A12DA5009151BE6A51F ----------------- >>> important notes : -> please do not touch the files becouse we can't decrypt it if you touch it -> please contact us today or soon a possible , becouse the leak operation should start , and we will not decrypt or recover you after time ----------------- - your leak post will be in our Blog : http://novadmrkp4vbk2padk5t6pbxolndceuc7hrcq4mjaoyed6nxsqiuzyyd.onion/ ----------------------------------------------------------------------------- Ransom -----------------------------------------------------------------------------
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (221)
Search, filter and paginate the victim timeline for Nova. Showing 201–221 of 221.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | SunMoon university id20298 View details | Korea, Republic of | Education | ||
|
The website sunmoon.ac.kr is the official online portal of Sun Moon University (SMU), a private, non-profit institution located in Asan... |
|||||
| Ransomware | educo id20278 View details | Spain | NGOs / Associations | ||
|
Educo El Salvador, the Salvadoran branch of Educo, an international non-governmental organization (NGO) dedicated to... |
|||||
| Ransomware | VS One Technology id20263 View details | Sri Lanka | IT | ||
|
VS One is a technology solutions provider based in Sri Lanka, established in 2019. The company specializes in distributing... |
|||||
| Ransomware | Municipality of Pisa id19960 View details | Italy | Public Sector | ||
|
The website comune.pisa.it is the official portal of the Municipality of Pisa, Italy. It serves as the primary online resource for residents, busine... |
|||||
| Ransomware | novaevo+ / T.consulT id19937 View details | Italy | IT | ||
|
"Novaevo" refers to a specialized software solution developed by T.consulT, an Italian company, designed to manage the lifecycle of technical documentation in industrial sectors, particularly aerospace and defense. The software ensures... |
|||||
| Ransomware | SJERP id19627 View details | Dominican Republic | Communication / Marketing | ||
|
The website sj.com.do is the official platform for SJ ERP, a comprehensive Enterprise Resource Planning (ERP) software developed by JoS... |
|||||
| Ransomware | rawafid id19620 View details | Saudi Arabia | Manufacturing / Engineering | ||
|
Established in 2008 and headquartered in Riyadh, Rawafid Industrial specializes in water infrastructure projects, including seawater and brackish water desalination, wastewater treatment... |
|||||
| Ransomware | Élan Sportif Nantes id19618 View details | France | Communication / Marketing | ||
|
this Victim has been unlisted and operation leak has been stoped , we stop attacks on schools non-profit companys from 1 April , please contact our department to receive decryptor ... |
|||||
| Ransomware | Tomio Ingeniería id19617 View details | Argentina | Other | ||
|
Data has been leaked shame on you and all who work with you |
|||||
| Ransomware | Ihara id19616 View details | Brazil | Other | ||
|
Data has been leaked shame on you and all who work with you |
|||||
| Ransomware | Pere Claver grup id19615 View details | Spain | Other | ||
|
Data has been leaked shame on you and all who work with you |
|||||
| Ransomware | Formosa Chang id19614 View details | Taiwan, Province of China | Other | ||
|
Data has been leaked shame on you and all who work with you |
|||||
| Ransomware | hasbco Company id19613 View details | United States | Services | ||
|
Data has been leaked shame on you and all who work with you |
|||||
| Ransomware | Al-Hejailan Group id19612 View details | Saudi Arabia | Services | ||
|
Data has been leaked shame on you and all who work with you |
|||||
| Ransomware | NewHotel cloud id19611 View details | Portugal | IT | ||
|
Data has been leaked shame on you and all who work with you |
|||||
| Ransomware | ARRCO LSM id19610 View details | Norway | Other | ||
|
Data has been leaked shame on you and all who work with you |
|||||
| Ransomware | Bio-Clima Service id19609 View details | Italy | Other | ||
|
Data has been leaked shame on you and all who work with you |
|||||
| Ransomware | bettininformatica - suporteon id19608 View details | Brazil | IT | ||
|
BThe website bettininformatica.com.br belongs to Bettin Soluções em Informática, a technology company based in Marília, São Paulo, Brazil. They offer services such as computer maintenance... |
|||||
| Ransomware | agromate id19607 View details | Malaysia | Agriculture / Food | ||
|
Agromate.com.my is the official website of Agromate Holdings Sdn Bhd, a leading Malaysian agricultural company specializing in fertilizer... |
|||||
| Ransomware | HELUKABEL id19605 View details | Germany | Manufacturing / Engineering | ||
|
The website www.helukabel.de is the official online presence of HELUKABEL GmbH, a German-based global leader in the manufacturing ... |
|||||
| Ransomware | DIALLOG id19604 View details | Canada | Telecommunications | ||
|
Diallog Telecommunications is a Canadian-owned and operated telecom company based in Toronto, established in 1998. Originally founded as ... |
|||||