RedAlert
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known as RedAlert, also tracked under the alias N13V, operates as a ransomware group. Open‑source reporting indicates the group is based in Russia. RedAlert emerged publicly in 2022 and is recognized for deploying ransomware that targets both traditional Windows servers and virtualized VMware ESXi environments. The group’s activity is characterized by the use of a custom encryptor that appends the .crypt extension to compromised files.
RedAlert’s observed victims include government entities in Latin America, with the National Consumer Service of Chile (Sernac) being a confirmed target. The group’s primary objective appears to be financial gain, achieved through a double extortion model that couples file encryption with threats to leak stolen data. By threatening to publish exfiltrated information unless a ransom is paid, RedAlert seeks to pressure victims into compliance. No public statements link the group to espionage or purely disruptive motives; its tactics are consistently tied to monetary extortion.
The ransomware payload used by RedAlert is identified as the RedAlert encryptor, also referred to as N13V in malware repositories. Upon execution, the malware encrypts files on Windows systems and on VMware ESXi hypervisors, rendering virtual machines inaccessible. Encrypted files are renamed with the .crypt extension, a marker that has been used in IoC sharing related to the group. RedAlert maintains a Tor‑hosted leak site where it threatens to release victim data, reinforcing the double extortion approach. Initial infection vectors have not been detailed in the available reporting, so the group’s preferred entry methods remain unspecified.
The most cited operation involving RedAlert occurred on August 25, 2022, when the ransomware struck Chile’s Sernac, encrypting files on its Windows and VMware ESXi servers. The attack disrupted the agency’s online services and forced a temporary shutdown of consumer‑protection functions while authorities investigated. Chilean officials released indicators of compromise, including file hashes and network artifacts, which security analysts linked to the RedAlert encryptor. Although the group’s leak site did not at that time list Sernac, the incident exemplified RedAlert’s use of double extortion against a public‑sector target. No further large‑scale campaigns have been publicly attributed to RedAlert in the sources provided.
Attribution to a specific nation‑state sponsor has not been established in public reporting; the group is described as a financially motivated criminal enterprise. The group’s location is noted as Russia in open‑source references, though no explicit state affiliation is cited. RedAlert operates independently of known ransomware cartels or affiliate programs in the disclosed material. Its activity remains confined to the ransomware niche, with no evidence of involvement in broader cyber‑espionage operations. Consequently, the actor is best understood as a Russia‑based ransomware group focused on monetary extortion through double‑encryption tactics.
Incidents
Attributed incidents are available to members.
1 incident