Redalert (also tracked as Red Alert) is a ransomware operator no longer publishing new disclosures. Darkfield has indexed 6 public victims claimed by this operator between July 14, 2022 and September 22, 2022. Redalert is a relatively obscure ransomware group that emerged in July 2022 with primarily financial motivations, operating on a smaller scale compared to major ransomware families. The group's origin and potential affiliations remain largely undocumented in public threat intelligence reporting, with limited information available from major security organizations regarding their operational structure or whether they operate as a Ransomware-as-a-Service model. Based on available data, Redalert has demonstrated a geographic focus on Western European targets, particularly concentrating their operations against entities in the United Kingdom and France, though their specific attack methodologies, initial access vectors, and technical capabilities have not been extensively documented in public security research. With only six known victims since their emergence, the group represents a minor player in the ransomware ecosystem, and their limited operational footprint suggests they may lack the sophistication and resources of more prominent ransomware operations. Current intelligence indicates minimal ongoing activity from this group, though definitive information about their operational status, potential disruption, or dissolution is not available in public reporting from major cybersecurity organizations.
How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.