Microsoft Disrupts RedVDS, Seizing Infrastructure Behind a Global Cybercrime Marketplace

Listen to this Post

Featured Image

Introduction: A Marketplace Built for Digital Crime

Microsoft has taken decisive action against RedVDS, a fast-growing cybercrime infrastructure provider that quietly fueled some of the most damaging online fraud campaigns of the past year. Through a coordinated international effort involving Europol and authorities in Germany, Microsoft seized critical RedVDS infrastructure, pushed the marketplace offline, and launched civil actions in both the United States and the United Kingdom. The move reflects a broader shift in how major technology companies are confronting cybercrime—not just by blocking attacks, but by dismantling the systems that make them scalable, affordable, and hard to trace.

The Core Announcement

Microsoft confirmed that RedVDS functioned as a subscription-based cybercrime service, offering disposable virtual servers to criminals for as little as $24 per month. These servers, often running unlicensed Windows software, allowed threat actors to launch phishing campaigns, host scam infrastructure, and conduct business email compromise at massive scale.

Financial Impact in the United States

According to Microsoft, RedVDS-enabled activity has resulted in at least $40 million in fraud losses across the U.S. since March 2025. These losses were not abstract statistics; they translated into real financial damage for organizations that trusted digital communications to manage payments and operations.

Victims Step Forward

Two U.S. organizations have joined Microsoft as co-plaintiffs in the civil action. Alabama-based H2 Pharma reported losses exceeding $7.3 million, while Florida’s Gatehouse Dock Condominium Association was defrauded of nearly $500,000. Their cases illustrate how cybercrime infrastructure directly converts technical access into financial harm.

Cheap Infrastructure, Massive Scale

Steven Masada, assistant general counsel at Microsoft’s Digital Crimes Unit, described RedVDS as a service that made fraud “cheap, scalable, and difficult to trace.” By offering disposable virtual machines with administrator privileges, the platform removed many of the technical barriers that once limited cybercriminal operations.

A Marketplace Designed for Abuse

RedVDS was not a simple hosting service. It operated like a modern SaaS platform, complete with a loyalty program and referral bonuses. These features incentivized repeat use and rapid growth, turning cybercrime into a subscription economy.

Law Enforcement Collaboration

Microsoft stated that the takedown was the result of joint operations with Europol and German authorities. This cooperation allowed investigators to seize infrastructure and take RedVDS offline, cutting off access for criminals who depended on the service.

Microsoft Customers in the Crosshairs

Microsoft acknowledged that many of its own customers were directly impacted. Since September 2025, RedVDS-enabled attacks led to the compromise or fraudulent access of more than 191,000 Microsoft email accounts across over 130,000 organizations worldwide.

Phishing at Industrial Volume

Over a single month, more than 2,600 RedVDS virtual machines sent Microsoft customers an average of one million phishing messages per day. This level of activity demonstrates how infrastructure-as-a-service has transformed cybercrime into an industrial operation.

Business Email Compromise at Work

RedVDS was heavily used in business email compromise schemes. Attackers leveraged compromised accounts to divert payments, impersonate executives, and manipulate financial workflows inside targeted organizations.

Real Estate Fraud Amplified

Microsoft revealed that more than 9,000 customers—many located in Canada and Australia—were directly affected by real estate-related fraud enabled by RedVDS. Realtors, escrow agents, and title companies were frequent targets due to their role in high-value transactions.

Industry-Wide Exposure

Threat intelligence analysis showed that RedVDS-supported scams extended beyond real estate. Construction, manufacturing, healthcare, logistics, education, and legal services were all hit, highlighting how broadly applicable the infrastructure was to different fraud models.

Technical Design That Lowered the Bar

Researchers noted that RedVDS offered unlicensed Windows-based RDP servers with full administrator control. This setup allowed even low-skill criminals to deploy phishing kits, malware, and scam portals with minimal effort.

Reused Images, Unique Fingerprints

The platform relied on a single cloned Windows host image across many servers. While this made operations efficient for RedVDS, it also created technical fingerprints that eventually helped researchers track and attribute activity.

Storm-2470 Identified

Microsoft tracks the group behind RedVDS as Storm-2470. Intelligence suggests that at least five additional cybercrime groups—and criminals previously associated with the Racoon0365 phishing service—also relied on RedVDS infrastructure.

A Long-Running Operation

RedVDS first launched in 2019 and remained operational for years, offering servers in the U.S., U.K., Canada, France, the Netherlands, and Germany. Its longevity underscores how quietly effective infrastructure-based cybercrime can be.

Growth in the Past Year

Researchers emphasized that RedVDS became especially prolific over the past year, facilitating thousands of attacks involving credential theft, account takeovers, and mass phishing campaigns.

Strategic Use of Third-Party Hosts

Rather than owning all its hardware, RedVDS rented servers from third-party hosting providers across multiple countries. This approach allowed it to provision IP addresses close to victims, bypassing location-based security filters.

Blending Into Normal Traffic

By operating from legitimate data centers, RedVDS traffic blended in with normal enterprise activity. This made detection harder and extended the lifespan of many attack campaigns.

Domains Seized, Operations Disrupted

Microsoft confirmed it seized two domains used to host the RedVDS marketplace and customer portal. These seizures not only disrupted current operations but also created pathways to identify the individuals behind the service.

Summary of the Original

A Global Cybercrime Engine Taken Offline

Microsoft, working alongside international law enforcement, dismantled RedVDS, a subscription-based cybercrime marketplace responsible for tens of millions of dollars in fraud losses. The platform sold cheap, disposable virtual servers—often running unlicensed Windows software—that enabled large-scale phishing, business email compromise, and payment diversion schemes. Victims included pharmaceutical firms, condominium associations, real estate professionals, and organizations across multiple industries. RedVDS infrastructure was linked to the compromise of over 191,000 Microsoft email accounts worldwide and the delivery of millions of phishing messages daily. The service operated since 2019, relied on third-party hosting providers across several countries, and was run by a group Microsoft tracks as Storm-2470. By seizing infrastructure and domains, Microsoft aims to disrupt shared cybercrime resources and identify those responsible.

What Undercode Say:

Infrastructure Is the Real Battlefield

The RedVDS takedown highlights a critical truth about modern cybercrime: attackers are increasingly interchangeable, but infrastructure is not. Platforms like RedVDS turn fraud into a service, allowing anyone with a credit card and criminal intent to launch attacks at scale.

Subscription Crime Mirrors Legitimate SaaS

RedVDS copied the growth mechanics of legitimate startups—low pricing, loyalty rewards, referrals—demonstrating how cybercrime evolves by mimicking the efficiency of legal tech businesses. This is no longer about lone hackers; it is about platforms.

Law Enforcement Alone Is Not Enough

Traditional arrests struggle to keep pace with digital crime. Microsoft’s approach—combining civil litigation, infrastructure seizure, and intelligence sharing—shows how private-sector action can fill enforcement gaps.

Email Remains the Weakest Link

The scale of compromised Microsoft accounts reinforces that email is still the primary attack vector. Even advanced security tools struggle when attackers control trusted infrastructure and legitimate-looking servers.

Real Estate as a Prime Target

High-value, time-sensitive transactions make real estate uniquely vulnerable. RedVDS amplified this weakness by providing localized IP addresses that made fraudulent emails appear routine and trustworthy.

Shared Hosting Enables Mass Abuse

By renting from multiple hosting providers, RedVDS exploited the neutrality of the cloud. This raises difficult questions about how hosting companies can better detect abuse without over-policing legitimate customers.

Technical Shortcuts Create Attribution Opportunities

Ironically, RedVDS’s reliance on cloned Windows images helped defenders identify it. Cybercriminal efficiency often trades resilience for speed, creating weaknesses that investigators can exploit.

Storm-2470 Signals Professionalization

The tracking of RedVDS as Storm-2470 shows how threat actors are now treated like enterprises, complete with branding, customer support, and product evolution.

Financial Losses Are Only the Surface

The reported $40 million in losses understates the real damage. Trust erosion, operational disruption, and long-term reputational harm ripple far beyond direct financial theft.

A Blueprint for Future Disruptions

Microsoft’s actions set a precedent. Targeting the economics and infrastructure of cybercrime may prove more effective than endlessly reacting to individual attacks.

Fact Checker Results

Verification of Claims

Microsoft’s reported figures align with publicly stated Digital Crimes Unit disclosures. ✅

Infrastructure seizure and Europol cooperation are consistent with established cross-border enforcement models. ✅

Exact total global losses likely exceed reported U.S. figures and remain partially unquantified. ❌

Prediction

The Next Phase of Cybercrime Disruption

More tech giants will pursue civil actions to dismantle shared criminal infrastructure. 🚀

Cybercrime marketplaces will fragment, becoming smaller and harder to track in the short term. ⚠️

Email security will shift toward infrastructure-level trust scoring rather than user behavior alone. 🔍

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: cyberscoop.com
Extra Source Hub (Possible Sources for article):
https://www.linkedin.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon