Netskope Threat Labs

RedAlert

ATP Sandbox Adv. HeuristicsAV

RedAlert (a.k.a. N13V) is a ransomware operation that emerged in 2022 targeting Windows systems and Linux VMware ESXi servers on corporate networks. Its encryptor supports both platforms, and its operators exfiltrate data and pressure victims through leak site threats. The family's ESXi support reflects the industry's shift toward encrypting virtualization infrastructure, where a single host compromise can affect dozens of virtual machines.

First seen
July 2022
Last seen
September 2026
Alert Name
Linux.Ransomware.RedAlert
Trojan.Linux.Ransom.RedAlert.A
Trojan.RedAlert.A
Win64.Ransomware.RedAlert