Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Redalert

RedAlert (also called N13V) is a ransomware group first observed in July 2022 that targets both Windows and Linux VMware ESXi servers, encrypting virtual machine files using the NTRUEncrypt algorithm and accepting only Monero for payment, conducting double-extortion attacks against corporate networks.

Victims
6
 
First Victim
2022-07-14
(est. attack date)
Discovery Date
2022-07-14
 
Last Seen
2022-09-22
 
Inactive Since
3yrs
more than
Avg Delay
N/A
attack→claim
Infostealer
66.7%
victims with domain
Countries
2
hit
Uptime
— avg (30d)
View Victims on World Map View Group Statistics

Known Locations (2)
Favicon Title Type Available Last Visit Server Info FQDN
favicon Board of shame No 2026-04-28T07:26:08 blog2hkbm6gogpv2b3uytzi3bj5d5zmc4asbybumjkhuqhas355janyd.onion
favicon Login No 2026-04-28T07:28:40 je2yizds7r4uidk6uixfxwjj5w7or2agit4aj66l4lrhdbrvr3lsymid.onion

Target
Top 5 Activity Sectors
  • Professional Services 3
  • Technology 1
Top 5 Countries
  • GB flag United Kingdom 1
  • FR flag France 1

Heatmap

Ransom Notes (1)

YARA Rules (2)

Victims (6)
Logo
Discovered: 2022-09-22 (3y ago)
No description available
Logo
Discovered: 2022-09-13 (3y ago)
No description available
Logo
Discovered: 2022-07-28 (4y ago)
No description available
Logo
Discovered: 2022-07-20 (4y ago)
No description available
Logo
Discovered: 2022-07-15 (4y ago)
No description available
Logo
Discovered: 2022-07-14 (4y ago)
No description available