RedAlert, also known as N13V, is a ransomware family and operation identified in 2022 that targets corporate Windows systems and Linux-based VMware ESXi infrastructure. Its ESXi-focused encryptor can terminate running virtual machines before encrypting virtual-machine-related data, enabling high-impact disruption of consolidated server environments. RedAlert uses hybrid cryptography incorporating AES and NTRUEncrypt, appends a variable crypt-style extension to encrypted data, and presents victims with ransom instructions. The operation has been associated with double-extortion activity, combining file encryption with theft and threatened publication of victim data. RedAlert has also been deployed as a third-party locker by financially motivated groups including Toy Ghouls and Vice Society. In Toy Ghouls incidents, the ransomware was observed deleting shadow copies, clearing Windows event logs, and removing Remote Desktop connection-history artifacts to hinder recovery and forensic investigation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Toy Ghouls uses ransomware from the LockBit and RedAlert families on Windows systems; RedAlert deletes shadow copies, clears Windows event logs and RDP history, and encrypts files.
We identified significant overlap in the encryption implementation observed in the “RedAlert” ransomware, a Linux locker variant targeting VMware ESXi servers, suggesting that both variants were developed by the same group of individuals.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Before starting the encryption, BlackCat shuts down the virtual machines with the esxcli command-line utility.
MITRE ATT&CK® Techniques Tactic Technique ID Technique Name Execution T1204 User Execution
When running the ransomware with the ' -w ' argument, the Linux encryptor will shut down all running VMware ESXi virtual machines using the following esxcli command: esxcli --formatter=csv --format-param=fields=="WorldID,DisplayName" vm process list | tail -n +2 | awk -F $',' '{system("esxcli vm process kill --type=force --world-id=" $1)}'
MITRE ATT&CK® Techniques ... Defense Evasion T1027 Obfuscated Files or Information
Windows event logs are cleared using wevtutil.exe or PowerShell; the group uses wevtutil cl to remove traces of activity.
RedAlert ransomware has manual operations, which means TAs execute the ransomware after a complete takeover of the victim system. The ransomware binary provides various options to the TAs for performing pre-encryption operations such as stopping all virtual machines running on VMware ESXi, Asymmetric cryptography performance tests, etc.
MITRE ATT&CK® Techniques Tactic Technique ID Technique Name ... Discovery T1012 ... Query Registry
MITRE ATT&CK® Techniques Tactic Technique ID Technique Name ... T1082 ... System Information Discovery
It scans the directory for the presence of files with .log, .vmdk, .vmem, .vswp and .vmsn extensions.
RedAlert ransomware has manual operations, which means TAs execute the ransomware after a complete takeover of the victim system. The ransomware binary provides various options to the TAs for performing pre-encryption operations such as stopping all virtual machines running on VMware ESXi, Asymmetric cryptography performance tests, etc.
Toy Ghouls uses RedAlert, Babuk, and LockBit to encrypt Windows, Linux, ESXi, NAS, local-disk, and mounted-network-resource data.
The Linux encryptor is created to target VMware ESXi servers, with command-line options that allow the threat actors to shut down any running virtual machines before encrypting files.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in related content as a ransomware operation targeting Windows and Linux VMware ESXi servers.
Previously used third-party ransomware family referenced as part of Toy Ghouls' tooling history before developing GenieLocker.
Previously used third-party ransomware referenced as background on Toy Ghouls' earlier operations.
Previously used by Toy Ghouls before the group transitioned to GenieLocker.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.