RedAlert (N13V) is a ransomware group targeting Windows and Linux VMware ESXi servers with double-extortion attacks.
Analyst brief
RedAlert (N13V) is a ransomware group targeting both Windows and Linux VMware ESXi servers, known for double-extortion attacks against corporate networks. They encrypt virtual machine files using the NTRUEncrypt algorithm and exclusively demand payment in Monero. Key TTPs include ransomware deployment on ESXi hypervisors and data exfiltration prior to encryption. Defenders should prioritize securing ESXi environments, monitoring for anomalous network activity, and tracking threat intelligence related to Monero transactions.
redalert
crime
RedAlert (also called N13V) is a ransomware group first observed in July 2022 that targets both Windows and Linux VMware ESXi servers, encrypting virtual machine files using the NTRUEncrypt algorithm and accepting only Monero for payment, conducting double-extortion attacks against corporate networks.