redalert
First seen July 14, 2022Active6 claimed victims
The claims below are reproduced as posted by redalert on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
RedAlert (also called N13V) is a ransomware group first observed in July 2022 that targets both Windows and Linux VMware ESXi servers, encrypting virtual machine files using the NTRUEncrypt algorithm and accepting only Monero for payment, conducting double-extortion attacks against corporate networks.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| www.bbadmin.com | September 22, 2022 | ransomware_live | — |
| groupg4.com | September 13, 2022 | ransomware_live | — |
| coarc.org | July 28, 2022 | ransomware_live | — |
| keystonelegal.co.uk | July 20, 2022 | ransomware_live | — |
| vahanen.com | July 15, 2022 | ransomware_live | — |
| syredis.fr | July 14, 2022 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).