Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors redalert

Description

RedAlert (also called N13V) is a ransomware group first observed in July 2022 that targets both Windows and Linux VMware ESXi servers, encrypting virtual machine files using the NTRUEncrypt algorithm and accepting only Monero for payment, conducting double-extortion attacks against corporate networks. Known victims: 6 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

RedAlert, also known as N13V, is amedium-tier ransomware group targeting Windows and Linux VMware ESXi servers. First observed in July 2022, they encrypt VM files using the NTRUEncrypt algorithm and demand Monero for decryption. Theiroperations are notable for their double-extortion tactics and limited targeting scope to date.

Goals & Targeting

RedAlert's strategic goals appear to be primarily financiallymotivated, with a focus on disrupting victims' operations through encryptionand extracting ransoms as the main revenue source. Thetargetingprofile focuses on corporate networks running VMware ESXi, suggestinga technical expertise in exploiting virtualization environments.The choice ofVMware likely reflects both ease of access and high value targetsdue to the critical nature of server infrastructure.Arrays andIndustries Critical Infrastructure, Financial Services, and Education sectorsare most exposed due to their reliance on virtualized environments.

Enhanced Description

RedAlert is a ransomware group that emerged in mid-2022,with distinct characteristics including its use of NTRUEncryptoRansomware for encryption and exclusive demand of Monero as paymentmethodology. The group primarily targets VMware ESXi environments, bothWindows-based and Linux-based. Ransom notes associated with the groupindicate demands for cryptocurrency payments only in Monerocurrency, which is common in ransomware groups seeking anonymity.Their primarymodus operandi involves encrypting virtual machine files usingNTRUEncrypt algorithm that has been documented before, but their exactinfrastructure and tools are not fully公开 disclosed. Their activity window betweenJuly and September 2022 shows a relatively short operational timelinewhich could indicate either focused campaigns or limited resources.

Key Capabilities

  • Ransomware targeting VMware ESXi servers
  • Encryption using NTRUEncrypt algorithm
  • Double extortion tactics (data exfiltration + encryption)
  • Payment in Monero cryptocurrency
  • Lateral movement within networks
  • Kill switch functionality in ransomware

MITRE ATT&CK Tactics

Credential Access
Exfiltration
Lateral Movement
Data Destruction

ATT&CK Techniques

T1059.003 - Obfuscated Files or Information
T1070 - Lateral Movement across a Network
T1566 - Data Exfiltration through Rogue Web Servers
T1204.002 - Data Encoding/Alias creation foransomware negotiation

Software / Tooling

N13V Ransomware

Campaigns & Victims

Redalert's campaigns between July and September2022 suggest a targeted approach, with known victims in sectors like Education and Critical Infrastructure. Their use ofdouble extortion indicates a sophisticated approach beyond simply encrypting data. Thegroup appears to have a quick operationaltempo based on their short firstand last seen windows, possibly indicating either focusedcampaigns or limited resources. Notable for their relatively small numberofknown victims and lack of large-scale campaigns typical of higher-tiergroups.

IOC Patterns

  • Ransomware file hashes associated with N13V
  • Monero wallet addresses used inprevious negotiations
  • Kill switch domains registered by the group
  • Network_traffic indicators linked to their killswitchmechanism

Recommended Actions

  • Implement network monitoring for unusual lateral movement patterns
  • Patch VMware environments against known vulnerabilities immediately
  • Enforce multi-factor authentication for all critical access points
  • Conduct regular backups and store them offline/air-gapped
  • Use EDR solutions to detect suspicious file encryption
  • Educate users about phishing attempts targetingVMware administrators

Suggested Tags

Ransomware
Financial-Gain
Organizational-Intelligence
Critical Infrastructure Attack

Confidence Assessment

High confidence in the identification of RedAlert as a ransomwaregroup based on clear encryption methodology and Monero-based demands.There is limited availability of detailed technical data regardingtheir specific tools and attack vectors beyond the known victimsand TTPs. The group's relatively short operational window and lackof widespread campaigns suggest medium confidence in their completecampaign patterns and future operations.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Financial-Gain
Organizational-Intelligence
Critical Infrastructure Attack

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Jul 14, 2022
Last Seen
Sep 22, 2022
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.