• 4 minuti
  • Pubblicato

Nova ransomware traced to real identity after global victim surge

Barbara Carminati Autrice di cybersecurity e privacy QWERTYmag

Scritto da Barbara Carminati

Nova ransomware traced to real identity after global victim surge QWERTYmag © www.qwertymag.it
Nova ransomware traced to real identity after global victim surge © www.qwertymag.it

Nova ransomware, born from the RALord group, has spread fast and hit victims worldwide. Investigators have now tied the operation to a specific person using digital clues and breach data, revealing the real face behind the attacks.

Nova's operator is no longer a ghost. The group's digital trail has led straight to a real person. This is one of the fastest-growing cybercrime threats of the past year. The mask is off.

Investigators didn't have a name at first. They tracked digital clues-Telegram usernames, chat IDs, and communication handles-left behind by Nova's team. The breakthrough came after a fight on an underground forum. Someone exposed the Telegram handle @freezqq. That handle pointed to a Russian phone number, several email addresses, and finally a VK profile. The name: Гла████ Максим Maksim Gla████. Records linked him to Bataysk, Rostov Oblast.

Unmasking the operator through digital traces

Nova's setup left marks everywhere. The same phone number and emails tied to @freezqq kept showing up in breach data. Every time, the trail circled back to the same person and place. This wasn't a one-off leak. Years of records confirmed the link. Malware logs tied to Maksim Gla████ showed more: credential trading and access sales. He was deep in the cybercrime world Nova calls home.

Other ransomware groups have slipped up the same way. As reported earlier, reused handles and infrastructure have exposed real attackers before.

In September 2026, Nova was identified as the most active ransomware operator in regional datasets tracking attacks on Middle Eastern organizations, confirming the brand's ongoing presence in the current threat landscape.

International Security Journal

From RALord to Nova a rapid evolution

Nova didn't start with that name. In March 2025, the group called itself RALord. They pushed a Rust-based ransomware, recruited affiliates on forums, and set up a data-leak site. Affiliates got 85% of ransom payments. The core team kept 15%. But RALord vanished within weeks. By April 1, 2025, the group had rebranded as Nova. The switch was done by the end of April. Threat intelligence firms quickly saw Nova was just RALord with a new name.

The numbers show how fast Nova grew. Cyjax found only three victims on the RALord leak site in late March 2025. By April 30, Nova's site listed 16 victims. AttackIQ said that by July 2026, Nova had hit about 180 victims in 38 countries. The hardest-hit sectors: technology, manufacturing, healthcare, education, and professional services.

Building a ransomware empire

Nova's team didn't just write code. They built a strong affiliate network. There was a dedicated panel, a recruitment system, and an encrypted chat platform for partners. Cyjax reported features like private and group chats, voice calls, and a €200 entry fee for early access. This setup let Nova grow fast. They pulled in many partners and spread far beyond their starting point.

Nova is still active. The Ransomnews ransomware tracker keeps logging new victims and updates through late September 2026. The threat isn't fading. Nova and other ransomware-as-a-service groups still put organizations in Europe and elsewhere at risk.

Investigators focused on hard evidence, not guesses. They mapped usernames, breach data, and malware logs across forums. This broke through the usual wall of anonymity. It wasn't just one leak or a careless post. The pattern of reused details and digital fingerprints led straight to Maksim Gla████.

Nova's shift from RALord to a global ransomware force-and the exposure of its operator-marks a turning point in cybercrime tracking. Ransomware groups can't hide behind new names and encrypted chats forever. Investigators are getting better at connecting digital traces across years and platforms. The myth of the untouchable cybercriminal is fading. For defenders and victims, Nova's story is a warning. Operational discipline matters as much as technical skill. Even the most careful threat actors can be unmasked by their own digital trail.

Articoli correlati