Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareRansomwareUsed by 1 actor

RedAlert

RedAlert is a name used in the provided content for at least two distinct malware contexts. First, RedAlert is described as a ransomware family, specifically a Linux locker variant targeting VMware ESXi servers. Reporting cited in the content notes significant code overlap between RedAlert and the PolyVice ransomware variant, suggesting they were developed by the same developer or developer group. RedAlert is also listed among ransomware families observed targeting ESXi environments, and Microsoft reportedly stated that Vice Society adopted the RedAlert variant in late September 2022. The content further states that Vice Society has a history of deploying third-party lockers including RedAlert.

Second, the content describes a malicious RedAlert Android APK observed by Palo Alto Networks Unit 42. This APK impersonated Israel’s official missile alert application and was distributed via Hebrew-language SMS links. Once installed, it collected sensitive device and user information including contacts, SMS logs, IMEI numbers, and email credentials. The APK reportedly used encrypted exfiltration mechanisms and anti-analysis protections.

Because the supplied material uses the same name for both an ESXi-targeting ransomware/locker and a malicious Android trojanized APK, attribution and classification should be handled carefully to avoid conflating the two. High-confidence details directly supported by the content are that RedAlert has been associated with VMware ESXi-targeting ransomware activity and separately with an Android impersonation malware campaign using SMS-based delivery and data theft capabilities.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Vanilla Tempest

We identified significant overlap in the encryption implementation observed in the “RedAlert” ransomware, a Linux locker variant targeting VMware ESXi servers, suggesting that both variants were developed by the same group of individuals.

via sentinelone labssentinelone.com
MITRE ATT&CK

Techniques & procedures

1 distinct technique documented for this family, organized by ATT&CK tactic.

Impact

1 technique
T1486Data Encrypted for ImpactEvidence1

In a recent intrusion, we identified a ransomware deployment that appended the file extension .ViceSociety to all encrypted files...

INDICATORS OF COMPROMISE

IOCs tracked for this family

3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
1 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
2 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
hash.sha1●●●●●●●●●●●●View more in app3 years ago
hash.sha256●●●●●●●●●●●●View more in app3 years ago
domain●●●●●●●●●●●●View more in app3 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching3

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping1

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.