logo

Microsoft, Law Enforcement Disrupt RedVDS Global Cybercrime Service

ID: f62b761c-abf8-567c-a7b3-ded6cbfa587e

STIX ID: report--f62b761c-abf8-567c-a7b3-ded6cbfa587e

Feed Name: Security Boulevard

Threat Score
80/100

Date Published: 2026-01-15

Date Updated: 2026-04-22

Author: Jeffrey Burt

...
...

Microsoft, Europol, and other authorities seized infrastructure and domains associated with RedVDS (attributed to actor Storm-2470), a subscription-based virtual desktop service that since 2019 — and heavily from 2025 onward — enabled large-scale phishing, BEC, account takeover, and real-estate/financial frauds; the service facilitated mass mailings (millions per day), leveraged cloned/unlicensed Windows images and AI-based impersonation, has been linked to roughly $40M in theft and impacts on hundreds of thousands of organizations worldwide, and relied on third-party hosting across multiple countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.