Inside RedVDS: How a single virtual desktop provider fueled worldwide cybercriminal operations
ID: d75419c6-99bb-5024-b96a-cc3a95362b9a
STIX ID: report--d75419c6-99bb-5024-b96a-cc3a95362b9a
Feed Name: Microsoft Security
Microsoft Threat Intelligence describes RedVDS, a criminal virtual dedicated server marketplace (tracked to operator Storm-2470) that rented cloned Windows RDP servers to multiple cybercriminals worldwide, enabling large-scale phishing, BEC, account takeover, and financial fraud; the report details the infrastructure and provisioning (single cloned Windows Server 2022 image with hostname WIN-BUNS25TD77J), common tools and attack chain, lists domains and IOCs, quantifies impact (roughly $40M USD in reported US losses), and provides mitigation guidance and Defender XDR detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
