A newly identified ransomware operation known as RedAlert, also referenced internally as N13V, has been observed targeting corporate networks by encrypting both Windows systems and Linux-based VMware ESXi servers. The Linux variant is built specifically for ESXi environments and can forcibly shut down running virtual machines before encrypting VM-related files, while encrypted data is renamed with a .crypt[number] extension and accompanied by a HOW_TO_RESTORE ransom note containing a Tor payment link. Researchers reported that the malware uses the NTRUEncrypt public-key algorithm and already shows relatively mature cross-platform capabilities despite appearing to be a newer operation.
RedAlert is also conducting double-extortion attacks, stealing data before encryption and threatening to publish it on a leak site if victims refuse to pay. Reporting on broader ransomware trends placed RedAlert alongside newer groups such as 0mega and Lilith, underscoring a rise in emerging crews with increasingly capable tooling. In that wider landscape, RedAlert stood out for its focus on enterprise virtualization infrastructure, especially ESXi hosts, adding to concerns that ransomware operators are continuing to prioritize high-impact targets that can disrupt large numbers of systems at once.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
The report detailed Lilith as a 64-bit C/C++ console executable that terminates processes and services, enumerates drives and files, encrypts data, appends the .lilith extension, and drops Restore_Your_Files.txt ransom notes. It also noted the note gives victims three days to negotiate before threatening to leak personal data via an onion site and TOX contact.
Cyble published a report highlighting three newer ransomware threats—RedAlert, 0mega, and Lilith—as part of a broader rise in ransomware activity. The report characterized 0mega as a new double-extortion gang and Lilith as a new ransomware tool used by operators.
Analysis revealed RedAlert's Linux encryptor could forcibly stop running VMware ESXi virtual machines before encrypting VM-related files, used NTRUEncrypt, appended .crypt[number] to files, and dropped HOW_TO_RESTORE ransom notes. The reporting also described its double-extortion model, Tor payment site, and Monero payment demand.
A new ransomware operation called RedAlert, internally named N13V, was identified targeting corporate networks. Reporting noted it encrypted both Windows systems and Linux VMware ESXi servers and that its leak site listed only one victim at the time.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.