RedAlert (N13V) Ransomware Attacks Both Windows and Linux Systems
RedAlert (N13V) is the name of a new ransomware strain that does more than most ransomware variants. RedAlert (N13V) can encrypt both Windows-based systems and servers running Linux VMware ESXi.
The names RedAlert and N13V, respectively, refer to the versions of the ransomware that encrypt Windows systems and Linux VMware ESXi.
The ransomware operates as expected, encrypting files and leaving them unopenable. Encrypted files receive a new extension that gets appended after their original one. A file named "document.txt" will turn into "document.txt.crypt[number string]" upon encryption.
The lengthy ransom note is deposited inside a plain text file named "HOW_TO_RESTORE.txt" and asks for payment in crypto, threatening to publish exfiltrated data if payment is not made within 72 hours. The full note goes as follows:
Your network was penterated
We have encrypted your files and stole large amount of sensitive data, including:
- NDA contracts and data
- Financial documents, payrolls, bank statements
- Employee data, personal documents, SSN, DL, CC
- Customer data, contracts, purchase agreements, etc.
- Credentials to local and remote devices
Encryption is reverssible process, your data can be easily recovered with our help
We offer you to purchase special decryption software, payment includes decryptor, key for it and erasure of stolen data
If you understand all seriousness of this sutation and ready to cooperate with us, follow the next steps:
1) Download TOR Browser from hxxps://torproject.org
2) Install and launch TOR Browser
3) Visit our webpage: hxxx://gwvueqclwkz3h7u75cks2wmrwymg3qemfyoyqs7vexkx7lhlteagmsyd.onion
On our webpage you will be able to purchase decryptor, chat with our support and decrypt few files for free
If you won't contact us in 72h we will start publishing stolen data in our blog part by part, DDoS site of your company and call employees of your company
We have analyzed financial documentation of your company so we will offer you the appropriate price
To avoid data loss and rising of the additional costs:
1) Don't modify contents of the encrypted files
2) Don't inform local authorities about this incident before the end of our deal
3) Don't hire recovery companies to negotiate with us
We guarantee that our dialogue will remain private and third-parties will never know about our deal
\%\%\%\%\%\%\%\%\%\%\%\%\%\%\% REDALERT UNIQUE IDENTIFIER START \%\%\%\%\%\%\%\%\%\%\%\%\%\%\%