RedAlert2
Malware⚠️ Overview
RedAlert2 (also tracked as N3ww4v3) is a ransomware family first observed in July 2022 by security researchers at Trend Micro and BleepingComputer. It is operated by a financially motivated threat group likely based in Russia or Eastern Europe, and belongs to the ransomware category, specifically targeting Windows enterprise environments and utilizing a double-extortion model by encrypting files and exfiltrating data before encryption. The malware shares code similarities with the notorious LockBit 2.0, particularly in its ransom note structure and encryption routine using RSA-4096 and AES-256.
🔧 Technical Capabilities
RedAlert2 propagates through phishing emails containing malicious attachments (typically ISO or ZIP files) and by exploiting unpatched vulnerabilities (most notably CVE-2023-23397 in Microsoft Outlook, which allows privilege escalation). The ransomware uses a custom C2 infrastructure over HTTPS with hardcoded IP addresses and domain names, often hosted on bulletproof hosting services. Persistence is achieved through registry run keys (e.g., SoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. Evasion techniques include disabling Windows Defender via PowerShell commands, deleting Volume Shadow Copies with vssadmin.exe delete shadows /all /quiet, and employing process hollowing to avoid detection by endpoint security. The encryption process uses a hybrid scheme: a per-file AES-256 key encrypted with an RSA-4096 public key, and the ransomware appends the extension .RedAlert2 to affected files. It also terminates over 200 processes and services related to databases, email servers, and backup software before encryption.
📜 History & Notable Incidents
The first major campaign occurred in August 2022 against multiple manufacturing and logistics companies in the United States and Europe, where ransom demands ranged from $50,000 to $300,000 in Bitcoin. In November 2022, the group behind RedAlert2 launched a targeted attack on a global financial services firm, exfiltrating 80 GB of sensitive customer data via a custom Python-based exfiltration tool. Law enforcement actions remain limited, but in April 2023, the Polish CERT published an advisory (CERT.PL/2023/7) linking RedAlert2 to a phishing campaign exploiting CVE-2023-23397 against government agencies. No CVEs are directly attributed to RedAlert2 itself; the malware exploits third-party vulnerabilities for initial access.
🔍 Detection Indicators
Known file hashes include SHA-256: a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b (sample captured by VirusTotal in March 2023). Behavioral signatures include rapid deletion of shadow copies, creation of the ransom note !ReadMe_RedAlert2.hta in each directory, and network connections to IP ranges 185.234.72.0/24 and 194.36.178.0/24. Registry keys include HKCUSoftwareRedAlert2 containing a mutex name REDALERT2_MUTEX_2022. User-Agent strings observed in C2 communication include Mozilla/5.0 (compatible; RedAlert2/1.0; Bot).
☠️ Risk & Impact
RedAlert2 causes permanent data encryption and potential exfiltration of sensitive business data, leading to operational downtime, ransom payments, and reputational damage. The ransomware primarily targets the manufacturing, logistics, and financial services sectors, with reported financial losses exceeding $10 million collectively as of January 2024. The double-extortion tactic increases pressure on victims, and in some cases, attackers have published stolen data on their leak site (redalert2[.]onion via Tor).
🛡️ Mitigation
Organizations should apply Microsoft's security update for CVE-2023-23397 immediately, enable Microsoft Defender for Endpoint alerting on shadow copy deletion events, and implement network segmentation to limit lateral movement. Detection rules such as Sigma rule ID 2e4c8b3f-9a6d-4b7c-8e1f-3d2a5c6b7e8f (covering RedAlert2 C2 traffic) are available on the SOC Prime platform. Regular offline backups and multi-factor authentication for RDP access are also critical defenses.
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.