HomeSecurityMicrosoft "hits" the infrastructure of the malicious RedVDS service

Microsoft “hit” the infrastructure of the malicious RedVDS service

Microsoft has announced that it has launched a “coordinated legal action” in the US and UK to disrupt a cybercrime service, called RedVDS , that has allegedly caused millions in losses.

Microsoft RedVDS

This effort is part of a broader law enforcement initiative in collaboration with authorities, which allowed Microsoft to seize the malicious infrastructure and take down the illegal service.

“For just $24 per month, RedVDS gives criminals access to disposable virtual computers, making fraud cheap, scalable, and difficult to detect,” said Steven Masada, assistant general counsel for Microsoft’s Digital Crimes Unit. “As of March 2025, malicious activity supported by RedVDS has resulted in approximately $40 million in losses in the United States alone.”

Crimeware-as-a-service (CaaS) offerings have become a highly profitable business model, transforming cybercrime from an exclusive domain requiring technical expertise into an underground economy where inexperienced and ambitious threat actors can execute complex attacks quickly and at scale.

See also: Hackers exploit c-ares DLL Side-Loading

These services cover a wide range of tools, from phishing kits to stealers and ransomware, essentially contributing to the “professionalization” of cybercrime.

Microsoft "hit" the infrastructure of the malicious RedVDS service

RedVDS: What the malicious service offers

Microsoft said RedVDS was advertised as an online subscription service that provides cheap, disposable virtual computers with unlicensed software (including Windows) allowing criminals to operate anonymously and send phishing emails, host fraud infrastructure, conduct business email compromise (BEC) schemes, steal accounts and facilitate financial fraud.

Specifically, it operated as a center for the purchase of unlicensed and inexpensive Remote Desktop Protocol (RDP) servers with full administrative control and no usage restrictions, through a feature-rich user interface.

RedVDS provided servers located in Canada, the U.S., France, the Netherlands, Germany, Singapore, and the U.K., and also offered a reseller panel for creating sub-users and providing access to manage the servers without sharing access to the main site.

See also: Researchers take down over 550 servers of the Kimwolf and Aisuru Botnets

An FAQ section on the website noted that users could use Telegram bot to manage their servers from the Telegram app instead of logging into the website. The service kept no activity logs, making it an attractive option for illegal use.

According to screenshots captured on the Internet Archive, RedVDS was advertised as a way to “increase your productivity and work from home with comfort and ease.”

The service, as administrators on the now-seized website said, was first founded in 2017 and operated on Discord, ICQ, and Telegram. The website went live in 2019.

Use of AI

“RedVDS is often combined with generative AI that help to more quickly identify high-value targets and create more realistic, multimedia email messages that mimic legitimate correspondence,” the company said, adding that “we have observed attackers further amplifying the scam by using AI tools for face swapping, video modification, and voice cloning to impersonate individuals and deceive victims.”

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Microsoft "hit" the infrastructure of the malicious RedVDS service

As of September 2025, attacks supported by RedVDS are said to have resulted in the breach of more than 191,000 organizations worldwide, highlighting the service's extensive reach.

Microsoft, which is tracking the developer and administrator of RedVDS under the alias Storm-2470, has identified a “global network of distributed cybercriminals” exploiting the infrastructure to hit multiple domains in the U.S., Canada, the U.K., France, Germany, and Australia.

See also: Ransomware: Hackers blackmail victims citing “compliance violations”

The ultimate goal of the attacks is to carry out highly convincing BEC scams, allowing threat actors to infiltrate legitimate email conversations with vendors and issue fraudulent invoices to trick targets into transferring funds to a mule account under their control.

Interestingly, Terms of Service prohibited customers from using the service to send phishing emails, distribute malware, transfer illegal content, scan systems for security vulnerabilities, or engage in denial-of-service (DoS) attacks. This suggests an apparent attempt by the threat actors to limit or avoid liability.

“Threat actors used RedVDS because it provided an extremely easy, low-cost, and resilient environment where they could launch and hide multiple stages of their activity,” Microsoft said. “Once deployed, the cloned Windows hosts provided attackers with a ready-made platform to research targets, create phishing infrastructure, steal credentials, compromise mailboxes , and perform impersonation-based financial fraud.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS