Nova, rebranded from RALord and operating as a ransomware-as-a-service outfit, has claimed 42 victims in the past 30 days against a total of 129 since first appearing on tracking in May 2026, indicating a high-tempo, active affiliate program. Claimed activity concentrates heavily in the technology sector (20 of the top listings), with secondary hits across education, transportation/logistics, manufacturing, and public sector entities, and geographic spread is broad but led by the US and Indonesia, with Vietnam, Brazil, and Peru also represented. The group is described in RaaS terms as relying on double-extortion, claiming to encrypt files while exfiltrating data to pressure victims with both a decryption demand and threat of public disclosure. Recent postings show repeated duplicate listings for the same organizations (SistNet, Digital Edge, VNSO) within days of each other, suggesting either re-listing of unresolved negotiations or affiliate-driven duplication in claims. No conclusions can be drawn here about actual technical intrusion methods beyond