RedAlert (also called N13V) is a ransomware group first observed in July 2022 that targets both Windows and Linux VMware ESXi servers, encrypting virtual machine files using the NTRUEncrypt algorithm and accepting only Monero for payment, conducting double-extortion attacks against corporate networks. Known victims: 6 1 ransom note(s) on file
Objectives
Executive Summary
RedAlert, also known as N13V, is amedium-tier ransomware group targeting Windows and Linux VMware ESXi servers. First observed in July 2022, they encrypt VM files using the NTRUEncrypt algorithm and demand Monero for decryption. Theiroperations are notable for their double-extortion tactics and limited targeting scope to date.
Goals & Targeting
RedAlert's strategic goals appear to be primarily financiallymotivated, with a focus on disrupting victims' operations through encryptionand extracting ransoms as the main revenue source. Thetargetingprofile focuses on corporate networks running VMware ESXi, suggestinga technical expertise in exploiting virtualization environments.The choice ofVMware likely reflects both ease of access and high value targetsdue to the critical nature of server infrastructure.Arrays andIndustries Critical Infrastructure, Financial Services, and Education sectorsare most exposed due to their reliance on virtualized environments.
Enhanced Description
RedAlert is a ransomware group that emerged in mid-2022,with distinct characteristics including its use of NTRUEncryptoRansomware for encryption and exclusive demand of Monero as paymentmethodology. The group primarily targets VMware ESXi environments, bothWindows-based and Linux-based. Ransom notes associated with the groupindicate demands for cryptocurrency payments only in Monerocurrency, which is common in ransomware groups seeking anonymity.Their primarymodus operandi involves encrypting virtual machine files usingNTRUEncrypt algorithm that has been documented before, but their exactinfrastructure and tools are not fully公开 disclosed. Their activity window betweenJuly and September 2022 shows a relatively short operational timelinewhich could indicate either focused campaigns or limited resources.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Redalert's campaigns between July and September2022 suggest a targeted approach, with known victims in sectors like Education and Critical Infrastructure. Their use ofdouble extortion indicates a sophisticated approach beyond simply encrypting data. Thegroup appears to have a quick operationaltempo based on their short firstand last seen windows, possibly indicating either focusedcampaigns or limited resources. Notable for their relatively small numberofknown victims and lack of large-scale campaigns typical of higher-tiergroups.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the identification of RedAlert as a ransomwaregroup based on clear encryption methodology and Monero-based demands.There is limited availability of detailed technical data regardingtheir specific tools and attack vectors beyond the known victimsand TTPs. The group's relatively short operational window and lackof widespread campaigns suggest medium confidence in their completecampaign patterns and future operations.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics