Storm-2470 is the Microsoft-tracked threat actor assessed to have developed and operated RedVDS, a cybercrime-as-a-service platform that provided low-cost disposable Windows-based virtual servers used to enable large-scale financially motivated fraud. The service has been publicly active since 2019 and was used to support phishing, credential theft, account takeover, business email compromise, and payment diversion operations. Reporting links RedVDS-enabled activity to substantial fraud losses and widespread compromise or fraudulent access affecting large numbers of organizations worldwide. Storm-2470’s operational role was infrastructure development and maintenance rather than a single intrusion set. RedVDS offered rapidly provisioned remote-access servers with full administrator control, cryptocurrency payment options, and minimal oversight, lowering the barrier for other criminal actors to conduct phishing and fraud at scale. Multiple financially motivated groups, including Storm-0259, Storm-2227, Storm-1575, and Storm-1747, were observed leveraging this infrastructure. A distinctive technical characteristic attributed to Storm-2470 was repeated cloning of RedVDS instances from a single Windows Server 2022 base image without changing core system identity, creating a uniform fingerprint across many hosts. The infrastructure was provisioned through automated virtualization workflows and rented from third-party hosting providers across several countries, enabling customers to obtain geographically proximate systems and better evade location-based defenses. RedVDS infrastructure was used to send high-volume phishing messages, host impersonation infrastructure, harvest credentials and session tokens, access victim mailboxes, and insert into legitimate business communications to redirect payments. Observed tooling on RedVDS instances included mass-mailing software, email harvesting tools, privacy and VPN software, and remote administration utilities. Activity associated with the platform affected sectors including legal services, construction, manufacturing, real estate, healthcare, logistics, and education. Storm-2470 is best characterized as a financially motivated cybercrime enabler whose infrastructure materially supported global business email compromise and related fraud ecosystems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates the RedVDS cybercrime subscription virtual server (VPS) service providing cloned Windows RDP VMs used at scale to enable phishing infrastructure, mailbox takeovers, and payment diversion schemes; associated with large-scale phishing activity and compromised accounts.
Microsoft-tracked actor assessed to have operated the RedVDS cybercrime-as-a-service platform, which provided disposable Windows-based RDP virtual servers used at scale for mass phishing, credential theft, business email compromise (BEC), and payment diversion fraud.
Microsoft-attributed activity cluster assessed as operating RedVDS, a cybercrime-as-a-service virtual desktop/VDS platform used at global scale to enable phishing, account hijacking, and fraud by multiple downstream criminal crews.
Tracked by Microsoft as the developer/maintainer of the RedVDS crimeware-as-a-service subscription platform providing disposable Windows-based RDP/VPS infrastructure used to enable phishing, BEC, account takeover, and financial fraud at scale. Operated by cloning a Windows Server 2022 VM image (QEMU/VirtIO) to rapidly provision new hosts, allegedly using a stolen Windows Eval 2022 license to reduce costs.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.