RedAlert is a ransomware family best known as a Linux locker targeting VMware ESXi environments. It has been used as a third-party encryptor by financially motivated extortion actors, including Toy Ghouls and Vice Society, and code overlap has been reported between RedAlert and other custom-branded ransomware payloads, suggesting development by a shared specialist ransomware developer or closely related developers. RedAlert is associated with attacks against virtualized enterprise infrastructure, where disruption of ESXi hosts can have outsized operational impact.
RedAlert is characterized in reporting as an encryption-focused malware family used in extortion operations. Its known role in intrusions is to encrypt victim systems rather than to serve as an initial access tool. The strongest platform attribution is to Linux and VMware ESXi, where it has been described as a locker variant aimed at virtual machine hosts.
Separately, the name RedAlert has also been used for a malicious Android APK that impersonated Israel’s official missile alert application during a regional conflict-themed social-engineering campaign. That Android malware reportedly harvested contacts, SMS logs, device identifiers, and email credentials, used encrypted exfiltration, and incorporated anti-analysis protections after being distributed through Hebrew-language SMS lures. Because the same name is applied to both a ransomware family and an Android espionage-style payload, the label is ambiguous across reporting and should be handled carefully in intelligence systems to avoid conflating distinct malware under one name.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Ce groupe utilisait auparavant des ransomwares tiers (RedAlert, LockBit, Babuk).
We identified significant overlap in the encryption implementation observed in the “RedAlert” ransomware, a Linux locker variant targeting VMware ESXi servers, suggesting that both variants were developed by the same group of individuals.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously used third-party ransomware family referenced as part of Toy Ghouls' tooling history before developing GenieLocker.
Previously used third-party ransomware referenced as background on Toy Ghouls' earlier operations.
Previously used by Toy Ghouls before the group transitioned to GenieLocker.
Previously used third-party ransomware family referenced as historical background for Toy Ghouls before adoption of GenieLocker.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.