New RedAlert Ransomware Targets Windows And Linux VMWare ESXi Servers

Share post:

A new ransomware operation uncovered by MalwareHunterTeam, has the ability to encrypt both Windows and Linux VMWare ESXi servers in attacks on corporate networks.

The ransomware is simply identified as RedAlert or N13V. According to researchers, the Linux encryptor used by the attacker is created to attack VMware ESXi servers with command-line options that allow the attackers to shut down all running virtual machines before they encrypt files.

When encrypting files, the ransomware utilizes the NTRUEncrypt public-key encryption algorithm. This algorithm supports different “Parameter Sets,” which offers different levels of security.

When encrypting files, the ransomware will only target files that are linked to virtual machines of VMware ESXi, including log files, swap files, virtual disks and memory files.

RedAlert’s Tor payment page displays the ransom note and offers a way to negotiate with the threat actors. While only one Linux encryption system was found on the page, the researchers explained that the page also contains hidden elements that show that there are also Windows decryption systems.

However, RedAlert/N13V only accepts the Monero cryptocurrency for payment. However, the Monero coin is not sold in the United States since it is a privacy coin.

The sources for this piece include an article in BleepingComputer.

SUBSCRIBE NOW

Related articles

Cyber Security Today, Week in Review for week ending Friday May 17, 2024

Welcome to Cyber Security Today. This is the Week in Review for the week ending Friday, May 17th,...

Cyber Security Today, May 17, 2024 – Malware hiding in Apache Tomcat servers

Malware hiding in Apache Tomcat servers, new backdoors found, and more Welcome to Cyber Security Today. It's Friday, May...

MIT students exploit blockchain vulnerability to steal 25 million dollars

Two MIT students have been implicated in a highly sophisticated cryptocurrency heist, where they reportedly exploited a vulnerability...

iOS update brings back photos users thought were permanently deleted

After a recent iOS update, a number of iPhone users have found themselves facing unexpected blasts from the...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways