RedAlert
RedAlert is Linux ransomware that targets VMware ESXi servers.
Profile source: Ransomware.live opens in a new tabRedAlert
Family profile
RedAlert is Linux ransomware that targets VMware ESXi servers. Reporting notes code overlap with PolyVice and adoption by Vice Society. This profile excludes the unrelated Android malware distributed as a fake emergency-alert application.
Operational record
Reporting
Research mentioning RedAlert
Toy Ghouls’ new toy: the GenieLocker ransomware - Malware News - Malware Analysis, News and Indicators
Researchers reported that the financially motivated Toy Ghouls group has deployed a new custom ransomware family, GenieLocker, against organizations in the Russian Federation, with manufacturing firms highlighted among the victims. Active since March 2026, the malware marks a shift away from third-party ransomware such as RedAlert, LockBit, and Babuk to a cross-platform encryptor built for Windows, Linux, and VMware ESXi environments. In a documented intrusion, the attackers reportedly entered through an OpenVPN connection belonging to a trusted external partner by using stolen valid credentials, then expanded access with OpenSSH, SoftPerfect Network Scanner, Mimikatz, PsExec, and PAExec. The Windows variant uses anti-debugging protections, requires a secret launch argument, terminates processes and services, and encrypts data with libsodium implementations of XChaCha20-Poly1305 and Curve25519-XSalsa20-Poly1305, while the Linux/ESXi build includes ESXi-specific behavior such as modifying /etc/vmware/welcome and targeting /vmfs/volumes; researchers said the group typically focuses on encryption rather than data theft or leak-site extortion.