RedAlert, also known as N13V, is a human-operated ransomware family discovered in July 2022 that targets Windows systems and Linux-based VMware ESXi environments on corporate networks. It is deployed after attackers have compromised the victim environment. Its ESXi-focused encryptor targets virtual-machine disks, memory, snapshots, swap data, and related logs, allowing attacks to disrupt virtualized infrastructure.
The Linux encryptor requires root privileges and supports configurable target paths, individual-file encryption, recursive processing, search-only operation, and cryptographic performance testing. It can forcibly terminate running virtual machines through VMware management utilities before encryption. RedAlert uses NTRUEncrypt for asymmetric key protection and creates ransom notes directing victims to a Tor-based payment and negotiation portal. Windows samples used by Toy Ghouls also delete shadow copies, clear Windows event logs, and erase RDP connection history, hindering recovery and forensic investigation.
The original RedAlert/N13V operation used double extortion, combining data theft with encryption and threatening publication of stolen information through a leak site. It demanded ransom payments in Monero. The ransomware has also been deployed by other financially motivated groups, including Vice Society and Toy Ghouls, also known as Bearlyfy, Labubu, and Laboo.boo. Toy Ghouls used RedAlert against Windows systems in attacks on Russian organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Ранее она использовала сторонние шифровальщики, включая RedAlert, LockBit и Babuk.
We identified significant overlap in the encryption implementation observed in the “RedAlert” ransomware, a Linux locker variant targeting VMware ESXi servers, suggesting that both variants were developed by the same group of individuals.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Before starting the encryption, BlackCat shuts down the virtual machines with the esxcli command-line utility.
MITRE ATT&CK® Techniques Tactic Technique ID Technique Name Execution T1204 User Execution
When running the ransomware with the ' -w ' argument, the Linux encryptor will shut down all running VMware ESXi virtual machines using the following esxcli command: esxcli --formatter=csv --format-param=fields=="WorldID,DisplayName" vm process list | tail -n +2 | awk -F $',' '{system("esxcli vm process kill --type=force --world-id=" $1)}'
MITRE ATT&CK® Techniques ... Defense Evasion T1027 Obfuscated Files or Information
RedAlert ransomware has manual operations, which means TAs execute the ransomware after a complete takeover of the victim system. The ransomware binary provides various options to the TAs for performing pre-encryption operations such as stopping all virtual machines running on VMware ESXi, Asymmetric cryptography performance tests, etc.
MITRE ATT&CK® Techniques Tactic Technique ID Technique Name ... Discovery T1012 ... Query Registry
MITRE ATT&CK® Techniques Tactic Technique ID Technique Name ... T1082 ... System Information Discovery
It scans the directory for the presence of files with .log, .vmdk, .vmem, .vswp and .vmsn extensions.
RedAlert ransomware has manual operations, which means TAs execute the ransomware after a complete takeover of the victim system. The ransomware binary provides various options to the TAs for performing pre-encryption operations such as stopping all virtual machines running on VMware ESXi, Asymmetric cryptography performance tests, etc.
Toy Ghouls uses RedAlert, Babuk, and LockBit to encrypt Windows, Linux, ESXi, NAS, local-disk, and mounted-network-resource data.
The Linux encryptor is created to target VMware ESXi servers, with command-line options that allow the threat actors to shut down any running virtual machines before encrypting files.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in related content as a ransomware operation targeting Windows and Linux VMware ESXi servers.
Previously used third-party ransomware family referenced as part of Toy Ghouls' tooling history before developing GenieLocker.
Previously used third-party ransomware referenced as background on Toy Ghouls' earlier operations.
Previously used by Toy Ghouls before the group transitioned to GenieLocker.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.