Executive Summary
RedVDS was a criminal hosting service that sold cheap, short-lived Windows virtual servers specifically designed to help criminals run scams, phishing, malware delivery, and account takeovers without being traced easily.
In a coordinated operation, Microsoft working with European law enforcement agencies, including Europol, seized RedVDS servers, domains, and backend systems, effectively shutting the service down and cutting off thousands of ongoing cybercrime campaigns.
This was not a data breach of one company — it was the removal of criminal infrastructure used globally to attack others.
What RedVDS actually was
RedVDS was not malware itself.
It was the engine behind the crimes.
Think of it like this:
- Criminals need computers on the internet to run scams
- Using home computers or major cloud providers gets them caught
- RedVDS sold “no-questions-asked” servers optimized for abuse
Key characteristics
- Windows-based virtual machines
- Very low cost (monthly subscriptions)
- No identity verification
- Fast provisioning (servers ready in minutes)
- Rapid server rotation to evade takedowns
- Hosted in jurisdictions slow to respond to abuse complaints
This made it ideal for:
- Phishing campaigns
- Business Email Compromise (BEC)
- Malware staging
- Credential harvesting
- Fraud payment redirection
- Command-and-control (C2) servers
How the attacks worked
Below is the typical RedVDS-enabled attack flow seen across investigations.
1. Initial Access / Entry Point
There was no single exploit or vulnerability used by RedVDS itself.
The service enabled multiple attack vectors, most commonly:
A. Phishing emails (most common)
- Fake invoices
- Fake Microsoft login alerts
- Fake DocuSign / OneDrive / SharePoint messages
- Fake supplier payment updates
Victims clicked links hosted on RedVDS servers.
B. Stolen credentials (account takeover)
- Credentials harvested via phishing pages
- Previously leaked credentials reused (credential stuffing)
- Access to email inboxes and cloud portals
C. Malware delivery (less common but observed)
- Malicious attachments (HTML, ISO, ZIP, LNK)
- Payloads staged or downloaded from RedVDS servers
2. Infrastructure Role of RedVDS
Once an attack started, RedVDS servers played several roles:
- Hosting phishing pages that looked like Microsoft 365, banks, or vendors
- Acting as redirectors to hide the final malicious destination
- Serving malware payloads
- Acting as C2 servers to receive stolen data
- Hosting admin panels for criminals to manage campaigns
The infrastructure was intentionally disposable.
If a domain was blocked, attackers spun up a new server within minutes.
3. Payloads and Tools Used
RedVDS itself did not provide malware, but it hosted and supported payloads, including:
Credential harvesting kits
- Fake Microsoft 365 login pages
- JavaScript-based credential stealers
- Real-time proxy phishing tools that bypass MFA
Malware families commonly hosted
- Loaders (PowerShell, HTA, JavaScript)
- Banking trojans
- Remote access tools (RATs)
- Info-stealers targeting browsers and email clients
Post-compromise tools
- Email rule manipulation scripts
- Inbox hiding rules
- OAuth app abuse
- Silent forwarding rules
4. Lateral Movement and Fraud Execution
Once access was gained:
- Attackers monitored victim inboxes
- Waited for real invoices or payment conversations
- Replaced bank account details
- Sent fraudulent payment instructions
- Redirected funds to mule accounts
This is classic payment diversion fraud, not ransomware.
What was impacted
There was no single victim organization.
RedVDS enabled attacks at scale across industries.
Most affected sectors
- Finance and accounting firms
- Healthcare providers
- Educational institutions
- Real estate and property management
- Manufacturing and supply chain companies
- Small and mid-sized businesses using Microsoft 365
Why these sectors
- Heavy email reliance
- Regular invoicing and payments
- Time-sensitive transactions
- Often weaker security controls
Was any vulnerability exploited?
No software vulnerability was required.
This was not a zero-day campaign.
The attacks succeeded because of:
- Stolen credentials
- Weak or absent MFA
- Human trust in email communications
- Poor email authentication configurations
- Lack of monitoring for inbox rule abuse
Was antivirus or EDR bypassed?
Yes, indirectly.
- Many attacks never dropped malware
- Phishing and email compromise bypass traditional antivirus
- Browser-based credential theft leaves no file on disk
- Living-off-the-land techniques (PowerShell, built-in tools)
This made detection harder for organizations relying only on endpoint protection.
Indicators of Compromise (IOCs)
Important note on IOCs
Law enforcement did not release a complete public IOC list to avoid tipping off remaining actors.
However, commonly observed indicators associated with RedVDS activity include:
Infrastructure indicators
- Short-lived VPS IP addresses
- Domains registered within days or weeks
- Domains mimicking Microsoft, banks, vendors
- Hosting tied to obscure ASNs with abuse history
Email indicators
- External emails impersonating internal users
- Unexpected payment change requests
- Reply-chain hijacking
- Look-alike domains (typosquatting)
Account indicators
- New inbox rules created without user knowledge
- Forwarding rules to external addresses
- OAuth apps added without consent
- Login activity from unusual geographies
Network indicators
- HTTP/HTTPS traffic to newly registered domains
- Encrypted outbound connections to unknown VPS IPs
- Repeated authentication attempts across accounts
What exactly was taken down
The takedown operation:
- Seized RedVDS backend servers
- Disabled customer control panels
- Removed domains used to sell the service
- Cut off payment systems
- Confiscated physical and virtual infrastructure
This instantly disrupted thousands of active campaigns.
Why this takedown matters
RedVDS was infrastructure, not a single gang.
Taking it down:
- Increased cost for cybercriminals
- Slowed active fraud operations
- Forced attackers to rebuild elsewhere
- Gave defenders visibility into attack patterns
This is a long-term disruption, not a permanent fix.
Lessons for organizations
- MFA must be enforced everywhere, without exceptions
- Monitor inbox rules and forwarding
- Verify payment changes out-of-band
- Block newly registered domains by default
- Train staff to recognize invoice fraud
- Treat email compromise as a major security incident
Final takeaway
RedVDS was the plumbing of modern cybercrime.
It didn’t hack companies itself — it enabled thousands of others to do so quietly and at scale.
The takedown didn’t end cybercrime, but it removed a critical piece of infrastructure, disrupted fraud globally, and showed that coordinated action between technology companies and law enforcement can meaningfully hurt criminal ecosystems.
