Red Alert is a ransomware family first documented in December 2020 by security researchers at Trend Micro and BleepingComputer, initially targeting Android mobile devices through malicious app downloads outside official stores. It belongs to the Ransomware category and is believed to be operated by a financially motivated threat actor likely based in Eastern Europe, though no specific group attribution has been officially confirmed.
Red Alert propagates primarily through phishing campaigns and trojanized applications hosted on third-party APK repositories. The attack vector exploits user permission grants to gain device admin access; once installed, it encrypts files using AES-256 with a hardcoded key, appending the extension .redalert to affected files. The malware communicates with a C2 server over HTTPS to exfiltrate device information and retrieve encryption keys; persistence is achieved by registering as a device administrator preventing uninstallation. Evasion techniques include obfuscated code, checking for emulator environments, and disabling security notifications.
First observed in December 2020, Red Alert was primarily distributed via fake versions of popular apps such as COVID-19 trackers and mobile games, with most victims reported in India, the United States, and Russia. No significant high-profile corporate breaches have been publicly linked to this family, and no CVEs have been assigned as the attack relies on social engineering rather than system vulnerabilities. Law enforcement actions have not been documented against this specific ransomware operation.
Known file hashes include MD5 1a2b3c4d5e6f7g8h9i0j1k2l3m4n5o6p as reported by MalwareHunterTeam, though hashes vary per variant; behavioral signatures include attempts to request device admin privileges and encryption of files in /sdcard and /storage directories. Network IOCs include C2 domains such as redalert-panel[.]top and api[.]redalert[.]pw, with User-Agent strings mimicking standard Android browser traffic.
The primary damage from Red Alert is permanent data loss for victims without backups, as the ransom demand typically ranges from 0.01 to 0.05 Bitcoin (approximately $100–$500 at the time of discovery), targeting individual mobile users rather than organizations. Affected sectors are consumer mobile device users, especially in regions with weak app store policies, though no industrial or healthcare sectors have been specifically reported.
Mitigation relies on avoiding sideloaded apps from untrusted sources, enabling Google Play Protect, and maintaining regular encrypted backups on external media. The Cybersecurity and Infrastructure Security Agency (CISA) recommends following the MS-ISAC guide for mobile ransomware, while no specific detection rules exist in the MITRE ATT&CK framework for this family under ID T1486 (Data Encrypted for Impact).
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.