Inside RedVDS: How a single virtual desktop provider fueled worldwide cybercriminal operations
Jan. 15, 2026, 11:31 a.m.
Description
RedVDS, a virtual dedicated server provider, has been utilized by multiple financially motivated threat actors for business email compromise, phishing, account takeover, and financial fraud. The service offers inexpensive Windows-based RDP servers with full administrator control, attracting cybercriminals worldwide. Microsoft's investigation revealed a global network targeting multiple sectors across various countries. RedVDS uses a single, cloned Windows host image, leaving unique technical fingerprints. The service operates through cryptocurrency payments and supports various digital currencies. Microsoft's analysis uncovered the infrastructure, provisioning methods, and tools deployed on RedVDS hosts, including mass mailers, email harvesters, privacy tools, and automation scripts.
Tags
Date
- Created: Jan. 14, 2026, 7:24 p.m.
- Published: Jan. 14, 2026, 7:24 p.m.
- Modified: Jan. 15, 2026, 11:31 a.m.
Indicators
- https://rd.redvds.com
Additional Informations
- Education
- Legal
- Manufacturing
- Real Estate
- Healthcare
- rd.redvds.com
- redvdspanel.space
- redvds.com
- redvds.pro
- Australia
- United Kingdom of Great Britain and Northern Ireland
- Germany
- Canada
- France
- United States of America