Uptime Hamster: 21d 6h 50mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza redalert

redalert

2 incidentes 1 paises 0 sectores threat-actor Ultimo: 2026-06-29
Aliases: N13V, RedAlert Doxware
Ver en IntelTracker → APTTrail →
RedAlert is a ransomware group that emerged in February 2022, also known as N13V, and is strongly associated with the Nokoyawa ransomware family. The group primarily targets businesses and critical infrastructure, employing double extortion tactics to encrypt sensitive data and pressure victims into paying ransoms by threatening to leak exfiltrated information. A distinguishing characteristic of RedAlert is its use of the uncommon NTRUEncrypt cryptographic algorithm for encryption, also seen in FiveHands ransomware. The group has shown an adaptive nature, with the Nokoyawa variant initially written in C and later rewritten in Rust by September 2022 to enhance performance and evasion capabilities. Its primary motivation is financial gain through these ransomware operations.

Aliases del actor

N13VRedAlert Doxware

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: redalert
DLS / onionofflineblog2hkbm6gogpv2b3uytzi3bj5d5zmc4asbybumjkhuqhas355janyd.onionCTI.FYI
DLS / onionofflineje2yizds7r4uidk6uixfxwjj5w7or2agit4aj66l4lrhdbrvr3lsymid.onionCTI.FYI
Tecnicas MITRE
T1059.001, T1078, T1486, T1569.002
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (OSINT)

United Arab EmiratesArgentinaAustriaBolivia, Plurinational State ofBrazilChileChinaSpainFinlandFrance

Sectores objetivo (OSINT)

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersHospitalsEnterprises & HoldingManufacturingConstructionPublic AdministrationEducational Services

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com