logo

Inside RedVDS: How a single virtual desktop provider fueled worldwide cybercriminal operations

ID: d75419c6-99bb-5024-b96a-cc3a95362b9a

STIX ID: report--d75419c6-99bb-5024-b96a-cc3a95362b9a

Feed Name: Microsoft Security

Threat Score
80/100

Date Published: 2026-01-14

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft Threat Intelligence describes RedVDS, a criminal virtual dedicated server marketplace (tracked to operator Storm-2470) that rented cloned Windows RDP servers to multiple cybercriminals worldwide, enabling large-scale phishing, BEC, account takeover, and financial fraud; the report details the infrastructure and provisioning (single cloned Windows Server 2022 image with hostname WIN-BUNS25TD77J), common tools and attack chain, lists domains and IOCs, quantifies impact (roughly $40M USD in reported US losses), and provides mitigation guidance and Defender XDR detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.