RedAlert (N13V) Ransomware Attacks Both Windows and Linux Systems

ransomware gang

RedAlert (N13V) is the name of a new ransomware strain that does more than most ransomware variants. RedAlert (N13V) can encrypt both Windows-based systems and servers running Linux VMware ESXi.

The names RedAlert and N13V, respectively, refer to the versions of the ransomware that encrypt Windows systems and Linux VMware ESXi.

The ransomware operates as expected, encrypting files and leaving them unopenable. Encrypted files receive a new extension that gets appended after their original one. A file named "document.txt" will turn into "document.txt.crypt[number string]" upon encryption.

The lengthy ransom note is deposited inside a plain text file named "HOW_TO_RESTORE.txt" and asks for payment in crypto, threatening to publish exfiltrated data if payment is not made within 72 hours. The full note goes as follows:

Hello, -

Your network was penterated

We have encrypted your files and stole large amount of sensitive data, including:

- NDA contracts and data

- Financial documents, payrolls, bank statements

- Employee data, personal documents, SSN, DL, CC

- Customer data, contracts, purchase agreements, etc.

- Credentials to local and remote devices

And more...

Encryption is reverssible process, your data can be easily recovered with our help

We offer you to purchase special decryption software, payment includes decryptor, key for it and erasure of stolen data

If you understand all seriousness of this sutation and ready to cooperate with us, follow the next steps:

1) Download TOR Browser from hxxps://

2) Install and launch TOR Browser

3) Visit our webpage: hxxx://gwvueqclwkz3h7u75cks2wmrwymg3qemfyoyqs7vexkx7lhlteagmsyd.onion

On our webpage you will be able to purchase decryptor, chat with our support and decrypt few files for free

If you won't contact us in 72h we will start publishing stolen data in our blog part by part, DDoS site of your company and call employees of your company

We have analyzed financial documentation of your company so we will offer you the appropriate price

To avoid data loss and rising of the additional costs:

1) Don't modify contents of the encrypted files

2) Don't inform local authorities about this incident before the end of our deal

3) Don't hire recovery companies to negotiate with us

We guarantee that our dialogue will remain private and third-parties will never know about our deal

\%\%\%\%\%\%\%\%\%\%\%\%\%\%\% REDALERT UNIQUE IDENTIFIER START \%\%\%\%\%\%\%\%\%\%\%\%\%\%\%

August 4, 2022