RedAlert is a ransomware family observed in 2022 that targets VMware ESXi environments. It is designed to encrypt virtualization-related files on ESXi hosts, creating infrastructure-level disruption by impacting virtual machines and associated storage. Reported targeting focuses on ESXi file types associated with virtual disks, memory, swap, snapshots, and logs. RedAlert supports configurable command-line parameters, including options to stop virtual machines prior to encryption and to perform recursive encryption. It has been reported to require root privileges on the target system. Its encryption implementation has been described as using AES together with NTRUEncrypt. The malware drops a ransom note after encryption and appends a variant-specific encrypted-file extension pattern. RedAlert is part of the broader trend of Linux and ESXi-focused ransomware operations that increasingly target virtualization infrastructure rather than only endpoint systems. Publicly available reporting identifies it as an ESXi-targeting ransomware family, but does not, at high confidence, establish a specific operator identity, country of origin, or a confirmed ransomware-as-a-service structure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named ransomware operation cited as one of several non-Babuk-based strains targeting VMware ESXi virtual machines.
Configurable ESXi-targeting ransomware that can stop VMs, recurse through directories, and requires root privileges for successful operation.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.