RedAlert, also referred to as N13V, is a ransomware family associated with financially motivated extortion activity. It emerged in 2022 as a cross-platform locker targeting corporate environments, with support for both Windows systems and Linux-based VMware ESXi servers. The malware is notable for its dedicated ESXi functionality, including the ability to stop running virtual machines before encrypting virtualization-related data, making it particularly disruptive in virtualized enterprise infrastructure.
RedAlert encrypts files on compromised systems and appends a variable ".crypt"-style extension. On ESXi, it targets virtual machine-associated data and supports recursive encryption and other operator-controlled command-line options. Public reporting describes its use of NTRUEncrypt in its encryption workflow, with AES also referenced in technical analyses of the Linux/ESXi variant. The malware drops ransom notes in affected directories and has been used in double-extortion operations in which data is stolen prior to encryption and later threatened with publication if the victim refuses to pay.
The ransomware has been observed as a third-party locker used by multiple threat actors rather than being exclusive to a single intrusion set. Reporting links its use to groups such as Vice Society and Toy Ghouls, and code overlap has also been noted between RedAlert and later custom-branded ransomware variants including PolyVice. RedAlert has been discussed alongside other ESXi-focused ransomware families because of its emphasis on virtual infrastructure disruption and its mature Linux support.
Separate reporting also mentions a malicious Android application using the RedAlert name that impersonated an Israeli missile alert app and harvested sensitive mobile data. However, that Android spyware activity is distinct from the better-known RedAlert/N13V ransomware family and should not be conflated with it.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Ce groupe utilisait auparavant des ransomwares tiers (RedAlert, LockBit, Babuk).
We identified significant overlap in the encryption implementation observed in the “RedAlert” ransomware, a Linux locker variant targeting VMware ESXi servers, suggesting that both variants were developed by the same group of individuals.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Before starting the encryption, BlackCat shuts down the virtual machines with the esxcli command-line utility.
MITRE ATT&CK® Techniques Tactic Technique ID Technique Name Execution T1204 User Execution
When running the ransomware with the ' -w ' argument, the Linux encryptor will shut down all running VMware ESXi virtual machines using the following esxcli command: esxcli --formatter=csv --format-param=fields=="WorldID,DisplayName" vm process list | tail -n +2 | awk -F $',' '{system("esxcli vm process kill --type=force --world-id=" $1)}'
MITRE ATT&CK® Techniques ... Defense Evasion T1027 Obfuscated Files or Information
RedAlert ransomware has manual operations, which means TAs execute the ransomware after a complete takeover of the victim system. The ransomware binary provides various options to the TAs for performing pre-encryption operations such as stopping all virtual machines running on VMware ESXi, Asymmetric cryptography performance tests, etc.
MITRE ATT&CK® Techniques Tactic Technique ID Technique Name ... Discovery T1012 ... Query Registry
MITRE ATT&CK® Techniques Tactic Technique ID Technique Name ... T1082 ... System Information Discovery
It scans the directory for the presence of files with .log, .vmdk, .vmem, .vswp and .vmsn extensions.
RedAlert ransomware has manual operations, which means TAs execute the ransomware after a complete takeover of the victim system. The ransomware binary provides various options to the TAs for performing pre-encryption operations such as stopping all virtual machines running on VMware ESXi, Asymmetric cryptography performance tests, etc.
A new ransomware operation called RedAlert, or N13V, encrypts both Windows and Linux VMWare ESXi servers in attacks on corporate networks.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in related content as a ransomware operation targeting Windows and Linux VMware ESXi servers.
Previously used third-party ransomware family referenced as part of Toy Ghouls' tooling history before developing GenieLocker.
Previously used third-party ransomware referenced as background on Toy Ghouls' earlier operations.
Previously used by Toy Ghouls before the group transitioned to GenieLocker.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.