TL;DR
Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.
Enroll Now and Save 10%: Coupon Code MWNEWS10
Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.
Nova did not begin as Nova.
The ransomware-as-a-service operation first emerged publicly in March 2025 under the name RALord, advertising a Rust-based ransomware payload, recruiting affiliates on underground forums, and operating a dedicated data-leak site. Affiliates were reportedly offered approximately 85% of successful ransom payments, while the core operators retained the remaining 15%. Within weeks, however, the RALord identity began to disappear.
On April 1, 2025, the operators introduced a separate affiliate-facing service carrying the name NOVA RaaS. By the end of the month, the transition was complete: RALord had been rebranded as Nova. Multiple threat-intelligence vendors subsequently treated the two names as the same ransomware lineage.
What initially looked like another newly launched ransomware service subsequently developed into a persistent operation. Cyjax counted only three victims on the RALord leak site in late March 2025. When the company updated its research on April 30, following the rebrand, Nova’s leak site contained 16 victim listings. By July 2026, AttackIQ reported that Nova’s leak site had accumulated approximately 180 claimed victims across 38 countries, with technology, manufacturing, healthcare, education, and professional services among the most represented sectors.
Nova’s operators also continued investing in the RaaS ecosystem around the ransomware itself. Public reporting documented an affiliate panel, recruitment infrastructure and a dedicated encrypted communications platform marketed to affiliates. Cyjax observed that the platform supported private conversations, group chats and voice communication, while access to the affiliate environment was advertised for €200 during the operation’s early period.
Our investigation, however, did not begin by attempting to guess who was behind Nova.
Instead, we focused on something much more difficult for an operator to repeatedly replace: communication infrastructure.
Nova and RALord exposed multiple persistent identifiers as the operation evolved, including Tox/qTox identifiers, Session IDs, Telegram usernames and other contact methods used by affiliates, victims and operators. Rather than treating usernames such as Nova, ForLord or RALordNOV as identities by themselves, we used these communication artifacts to expand the surrounding persona cluster.
The objective was to identify as many historical accounts as could defensibly be connected to the same operational environment, then investigate each of those accounts for older mistakes.
The strategy eventually produced a useful bridge.
A communication artifact associated with Nova also appeared around the personas ForLord and RALordNOV. Historical forum activity connected to the same cluster led to a dispute involving ForLord and another underground user, scrud, during which the Telegram identifier @freezqq was exposed.
That username was markedly different from the purpose-built ransomware personas.
Unlike Nova or RALordNOV, freezqq had a deeper historical footprint.
Following it led to the Russian telephone number +7951538████, several email addresses containing the recurring freez alias, a Telegram identity displaying the name Максим, historical account registrations, a VK profile, records placing the individual in Bataysk, Rostov Oblast, and eventually the identity:
Гла████ Максим Maksim Gla████.
The result did not come from starting with Gladkin and attempting to find connections to ransomware. The direction was the opposite.
We began with Nova’s operational infrastructure and repeatedly expanded the surrounding identity cluster until one of the communication artifacts crossed from the ransomware ecosystem into a much older personal footprint.
From RALord to Nova
To understand why the identity pivots matter, it is first necessary to understand how quickly the operation itself evolved.
RALord appeared publicly in March 2025 as a ransomware-as-a-service operation built around a Rust-based encryptor. Files encrypted by early variants received the .RALord extension, and ransom notes instructed victims to communicate with the operators through qTox. The operation combined file encryption with data theft, allowing the group to threaten non-paying victims with publication through a Tor-hosted data-leak site.
From the beginning, RALord attempted to construct a broader commercial ecosystem.
Cyjax documented the group’s affiliate program and its 85/15 revenue split, under which affiliates retained most successful ransom payments. RALord additionally advertised access to its encryption tooling, offered third parties the ability to advertise stolen datasets through its Tor infrastructure and promoted other services connected to cybercrime monetization. The same reporting identified ForLord as a persona active around the operation.
Recruitment had already begun by approximately March 19.
Posts associated with the operation sought individuals with penetration-testing and vulnerability-exploitation experience, while development-related requirements referenced Python and Rust. The recruitment activity indicated that the operators were not simply looking for customers for an encryptor: they were attempting to expand the human infrastructure behind the service.
The first visible indication of the Nova identity appeared less than two weeks later.
On April 1, RALord introduced a separate onion service branded NOVA RaaS, apparently intended to support affiliate association. By late April, RALord announced the wider brand transition and the original identity effectively gave way to Nova.
The precise motivation for the rebrand remains less clear than the relationship itself.
Cyjax noted at the time that RALord’s name resembled the established RAWorld/RAGroup ransomware operation, but did not attribute the rename to a specific cause. Later reporting cited statements by Nova’s operators claiming that RAWorld had approached them regarding collaboration and that the rebrand followed their refusal. That explanation is actor-supplied and should therefore not be treated as independently verified.
What is much better supported is that RALord and Nova represented the same evolving operation.
S2W assessed the relationship with high confidence and separately identified @ForLord as a recruitment persona, alongside another recruitment identity used on BreachForums. During the second half of 2025, S2W observed 77 relevant deep- and dark-web activity records in its analysis, of which 26 were related to Nova, reflecting the operation’s sustained promotion and continued development rather than a one-time rebrand followed by inactivity.
By 2026, Nova had grown far beyond the relatively small RALord operation initially observed in March 2025.
Expanding the Nova Persona Cluster
When attempting to identify a threat actor, starting with the actor’s most recognizable username is rarely enough.
Names such as Nova, ForLord, or RALordNOV are disposable. An operator can create another username within minutes and any forum user can use these usernames to fake that they belongs to a well-known and popular threat group, so sommunication identifiers are often more useful.
An operator running a ransomware service needs affiliates to reach them. Victims need somewhere to negotiate. Potential partners need a mechanism for establishing contact. Consequently, Tox IDs, Session identifiers, Jabber addresses, Telegram accounts and email addresses are often reused for longer periods than the public personas surrounding them.
Rather than attempting to immediately determine who controlled the Nova account, we wanted to know how many online personas could we reliably connect to the Nova/RALord operation
We collected the contact methods associated with Nova and RALord and began pivoting on them across historical forum records. Each discovered account was then treated as a new pivot.
For every persona, we looked for:
- additional Tox or Session IDs;
- Telegram usernames;
- email addresses;
- historical forum posts;
- reused contact information;
- exposed IP addresses;
- archived profile information;
- credential or breach exposure;
- and usernames used outside the ransomware ecosystem.
We wanted to create the largest defensible cluster of accounts around the operation. Once that cluster existed, we could investigate every persona individually for historical mistakes.
Starting With Nova
One of the accounts in our dataset used the username Nova, the account was associated with a forum advertisement titled: (RaaS) Nova 2.0 (Premium Program) | (Katana Version)

The same Nova cluster contained one of the group’s onion services as well as a Tox identifier used for communication.
Nova username was leaked in RaidForums data breach and associated with the email address: [email protected]
The email had an additional social-media footprint, including an Instagram association.

At this stage, however, none of those artifacts were sufficient to establish a real-world identity.
The Tox-linked artifact associated with Nova was not exclusive to that account.
One Contact Method, Multiple Ransomware Personas
The same chain exposed another identifier associated with ForLord and RALordNOV
ForLord had already been independently linked to RALord’s early operation and recruitment activity.
We were therefore no longer correlating two accounts because their usernames contained similar ransomware-related terms. An operational communication artifact connected them.

The ForLord and scrud Scam Dispute
While reviewing historical forum material associated with the usernames we got, we identified two related threads
The threads involved a dispute between ForLord and scrud, with the users accusing each other of scamming.
For identity research, disputes between criminals can be particularly useful.
Actors who normally maintain strict separation between personas may expose additional screenshots, payment information, contact methods, chat accounts, or historical identifiers while attempting to prove that another user is dishonest.
ForLord later published a thread warning that one of Nova’s affiliates had been scammed. The post included both a Session ID already associated with the Nova operation and a Telegram username. This left us with two plausible interpretations.
The first is that the scammer was an individual operating within, or closely alongside, Nova potentially an administrator who had scammed one of the group’s own affiliates. Under this scenario, ForLord was exposing the individual’s Telegram account together with the Session ID used by that operator.
The second possibility is simpler: ForLord was warning other users about an external scammer, while the Session ID and Telegram username appeared as contact details or signature information attached to the post.
Either interpretation was useful for our investigation.
In the first case, the Telegram account would belong directly to an individual operating within the Nova ecosystem. In the second, the identifier was still exposed inside a thread authored by a known RALord/Nova persona and tied to contact infrastructure already associated with the group.

Why @freezqq Mattered
Ransomware-specific usernames frequently have limited historical footprints. A username such as Nova may have been created specifically for the operation. The same applies to RALordNOV.
Older, more personal usernames are different. If an actor used the same Telegram identifier before becoming involved in ransomware operations, that account may connect to years of historical activity.
We therefore pivoted on @freezqq The Telegram identifier produced several results.
Our Telegram Intelligence Feature in CCI Portal associated it with telegram account named Максим as well as the telephone number +7951538████

The Phone Number Pivot
Searching the telephone number +7951538████, which we obtained from the Telegram account, across historical breach datasets produced a substantial amount of useful information.
The number appeared alongside the name:
Гла████ Максим (Gla████ Maxim)
Notably, this was the same name displayed on the Telegram account from which the telephone number had originally been obtained.
The same number was also associated with several email addresses, including:
- 45████[email protected]
- 7████[email protected]
- maksimgla████[email protected]
- maksimgla████@gmail.com
Additional records consistently placed the identity in:
Батайск Bataysk, Russia
The datasets also contained historical payment-card metadata associated with the same telephone number, including the card:
559900██████6387
Cross-Breach Corroboration
The information associated with +7951538████ did not originate from a single leak. Searching the number across multiple historical breach datasets produced records spanning several years and services, with the same core identifiers repeatedly converging on Гла████ Максим (Gla████ Maksim) .
One of the earliest useful records came from a 2022 1win dataset. The entry contained the first name Максим, telephone number +7951538████, email address 45████[email protected], country code RU, and the IP address: 178.76.232.106
A separate Gloria Jeans dataset contained another strong correlation. A record registered on 11 September 2022 associated the same telephone number with:
- Гла████ Максим
- Date of birth: 12 September 2007
- Email: 7████[email protected]
Again, this independently tied the telephone number to both the Gla████ identity and the freez email pattern.
Further leaked datasets continued to repeat the same information.
Records attributed to dobro.ru associated the number and the full name Гла████ Максим Алексеевич with several email addresses, including 7█████[email protected], ma███[email protected], and maksimgla████[email protected]. The records show registrations dating back to September 2023, while the ma███sp07 entry was later updated in April 2025.
A 2024 Burger King Russia dataset linked the same phone number to Максим, date of birth 12 September 2007, 7████[email protected], and Bataysk. The record also listed the Europe/Moscow timezone and was dated 16 August 2024. Another CDEK-related record from the same period associated the phone number with the fuller name Гла████ Максим Алексеевич and again placed the individual in Bataysk, Russia.
The breach-derived footprint became considerably more detailed in later records.
Several datasets associated the identity with the Russian taxpayer identifier:
ИНН / INN: 61410████137
and the insurance identifier:
СНИЛС / SNILS: 159████7375
The same records listed passport number 60216████1 issued by the Main Directorate of the Ministry of Internal Affairs for Rostov Oblast, with subdivision code 610-021. The source records are not completely consistent on the passport issuance date: multiple entries list 27 September 2021, while another record lists 27 September 2022. We therefore retain the discrepancy rather than attempting to resolve it from the leaked data alone.
More detailed breach records placed Gla████ in Bataysk, Rostov Oblast, including addresses recorded as Rostov Oblast, Bataysk, 10-ya Liniya Street, 8██ and: Rostov Oblast, Bataysk, DNT Trud, 8██
The records also list Bataysk, Rostov Oblast as his place of birth.
A 2025 financial-services dataset contained the same name, date of birth, phone number and Bataysk location alongside a 1,000 RUB credit application marked as rejected. The dataset unusually described the employment status as Не работает/Пенсионер (“not working/pensioner”), which is inconsistent with other records associated with the identity and should therefore not be treated as reliable biographical information.
The telephone number also appeared in an hh.ru resume dataset. That record identified the individual as Гла████ Максим Алексеевич, using 45████[email protected], and listed his location as Bataysk, Russia. The resume described him as a general laborer (Разнорабочий) with one year of experience and a requested monthly salary of 100,000 RUB. The account was registered on 1 August 2025.
More recent leaked records continued to connect the same identity cluster.
A 2026 dataset linked Гладкин Максим Алексеевич, 45████[email protected], the telephone number, passport 60216████1, and Bataysk. Other records associated 7████[email protected] with a Leader-ID account in Bataysk, while a Gosuslugi-related entry reported the telephone-number account as confirmed and active as of 19 June 2026.
One particularly interesting dataset came from langame.ru, a platform associated with gaming clubs. The record identified Гла████ Максим Алексеевич and +7951538████, and linked the account to CyberX Bataysk. It recorded activity across seven clubs, a cumulative top-up amount of 60,724 RUB, last account activity on 22 June 2026, and a last recorded gaming session on 9 April 2026.
Taken together, the breach data provided a much broader picture than the initial phone-number result. Across records originating from unrelated services and different years, the following attributes repeatedly converged:
| Attribute | Repeatedly observed value |
|---|---|
| Name | Гла████ Максим Алексеевич / Гла████ Максим / Максим |
| Date of birth | 12 September 2007 |
| Phone | +7951538████ |
| Emails | 7████[email protected], 45████[email protected], maksimgla████[email protected], ma████[email protected] |
| Additional emails | |
| INN | 61410████137 |
| SNILS | 159████7375 |
| Passport | 60216████1 |
| Location | Bataysk, Rostov Oblast, Russia |
| 1win IP | 178.76.232.106 |
The repeated appearance of freez is particularly relevant. Our investigation reached the telephone number through the Telegram username @freezqq; we did not begin with Gla████‘s name. Finding the same phone number repeatedly associated with both 45████[email protected] and 7████[email protected] across independent breach datasets provided an additional link between the Telegram identity and the real-world records.
Additional Account Corroboration
The Sherlock enrichment report produced several additional accounts associated with the telephone number.
Most importantly it identified a MAX account displaying the name Гладкин Максим, and a VK profile at vk.com/id574████64, displayed in the report under the name Равинский Максим. The same phone number was also reachable through WhatsApp.
The report additionally returned banking-name matches from Alfa Bank, Ozon Bank, Tinkoff Bank, and YooMoney, each displaying a shortened identity consistent with Максим Алексеевич Г.
The aggregated dataset also listed registrations or activity across numerous services, including 1win, Gloria Jeans, Burger King Russia, CDEK, Vitaexpress, dobro.ru, hh.ru, Leader-ID, Gosuslugi, Avito, T2, budgett.ru, zaymer.ru, langame.ru, and several financial-service datasets.
Additional Exposure Through Malware Logs
Further investigation identified what appears to be a malware/stealer log associated with Gladkin, exposing additional account credentials and providing another view into the system used by the individual.
The collected material included a screenshot of the desktop environment. The system was running Windows with the interface set to Russian, while the browser contained several Russian-language services and a tab opened to BHF pro forum.

More importantly, credentials associated with the same identity were present in leaked malware-log data, including account passwords. This provided an additional source of historical exposure separate from the breach datasets discussed earlier.
Underground Activity Recovered From the Stealer Log
The malware-log data provided more than another copy of Gladkin’s credentials. It also preserved a considerably broader history of the freez persona and its interaction with underground services.
Across the recovered browser and form artifacts, we observed repeated use of several closely related aliases, including freezq, freezqq, and freezqqq, alongside identifiers already established elsewhere in the investigation: 45████[email protected], 7████[email protected], maksimgla████[email protected], and the telephone number associated with Gla████.
The log also contained profile-form artifacts in which freezqq was entered as a Telegram contact alongside qTox identifiers. This was particularly noteworthy given that our investigation of Nova had itself relied heavily on persistent communication identifiers such as Tox and Session to move between otherwise disposable forum personas. While the qTox identifiers recovered from the malware log should not automatically be treated as Nova infrastructure, they provide further evidence that the freezqq identity used the same type of communication channels common throughout the underground ecosystem.
The recovered activity also contained repeated references to compromised-access trading and credential-oriented activity. Search and form-history artifacts referenced OWA, RDWeb, Citrix, cPanel, WordPress administrative access, URL:login:password datasets, VPN/RDP access, email checkers, and breached or credential datasets. Several form subjects referenced the sale or purchase of remote access and large credential collections.
One artifact also contained the phrase “HACKUS MAIL CHECKER 2 cracked by Maksim.”
Conclusion
Nova’s operators relied on identities that were designed to be disposable. Usernames could be replaced, forum accounts abandoned, and the RALord name itself was eventually discarded in favor of Nova, But the communication infrastructure was harder to replace.
Our investigation began by pivoting on the contact methods exposed around the RALord/Nova operation rather than attempting to identify a specific person. Reused Tox and Session identifiers allowed us to move between multiple forum personas and expand the number of accounts available for investigation.
That process eventually led to a forum dispute involving ForLord, where the Telegram username @freezqq surfaced alongside a Session identifier already relevant to the Nova cluster.
The telephone number connected to @freezqq repeatedly appeared across unrelated breach datasets alongside the same freez email addresses, the same location in Bataysk, and ultimately the identity Гла████ Максим Алексеевич Maksim Gla████. The relationship was reinforced by records spanning several years rather than a single leaked entry.
The later discovery of stealer-log material added another layer. The collection repeatedly contained Gla████-linked telephone numbers, email addresses and freez aliases, while also preserving qTox contact fields and extensive interaction with credential, remote-access and underground-forum material. Although individual browser artifacts cannot establish authorship of every activity they contain, the broader footprint is consistent with an identity operating inside the same cybercrime ecosystem in which the Nova investigation began.
Article Link: Unmasking a Nova Ransomware Operator: Following Reused Contact Methods to a Real-World Identity - DeXpose