Orova is a newly emerged ransomware extortion group that has been active since mid-2026. They focus on compromising corporate networks and leveraging data exfiltration to enforce ransom payments, utilizing a dedicated data leak site on the dark web to publish stolen files if demands are not met.
Key insights
•Orova employs a data leak site to pressure victims into paying ransom.
•The group's operations are aligned with modern data-theft extortion tactics.
•They target corporate networks primarily.
•Orova has been active since mid-2026.
•Victims face public exposure of stolen proprietary data.
•Their model includes both data encryption and data exfiltration.