Security News > 2022 > July > New RedAlert Ransomware targets Windows, Linux VMware ESXi servers

A new ransomware operation called RedAlert, or N13V, encrypts both Windows and Linux VMWare ESXi servers in attacks on corporate networks.
The Linux encryptor is created to target VMware ESXi servers, with command-line options that allow the threat actors to shut down any running virtual machines before encrypting files.
When encrypting files, the ransomware will only target files associated with VMware ESXi virtual machines, including log files, swap files, virtual disks, and memory files, as listed below.
Like almost all new enterprise-targeting ransomware operations, RedAlert conducts double-extortion attacks, which is when data is stolen, and then ransomware is deployed to encrypt devices.
When a victim does not pay a ransom demand, the RedAlert gang publishes stolen data on their data leak site that anyone can download. Currently, the RedAlert data leak site only contains the data for one organization, indicating that the operation is very new.
While there has not been a lot of activity with the new N13V/RedAlert ransomware operation, it is one that we will definitely need to keep an eye on due to its advanced functionality and immediate support for both Linux and Windows.
News URL
Related news
- Over 37,000 VMware ESXi servers vulnerable to ongoing attacks (source)
- New VanHelsing ransomware targets Windows, ARM, ESXi systems (source)
- LightSpy Expands to 100+ Commands, Increasing Control Over Windows, macOS, Linux, and Mobile (source)
- Like whitebox servers, rent-a-crew crime 'affiliates' have commoditized ransomware (source)
- VanHelsing ransomware emerges to put a stake through your Windows heart (source)
- Broadcom warns of authentication bypass in VMware Windows Tools (source)
- RedCurl cyberspies create ransomware to encrypt Hyper-V servers (source)
- Update VMware Tools for Windows Now: High-Severity Flaw Lets Hackers Bypass Authentication (source)
- Recent Windows Server 2025 updates cause Remote Desktop freezes (source)
- Outlaw Group Uses SSH Brute-Force to Deploy Cryptojacking Malware on Linux Servers (source)