Storm-2227 is a financially motivated cybercriminal threat actor tracked by Microsoft. It has been identified as one of several groups that leveraged the RedVDS cybercrime-as-a-service platform, a provider of low-cost Windows-based virtual private servers with RDP access that enabled anonymous, rapidly replaceable infrastructure for fraud operations. Reporting links Storm-2227 to infrastructure overlap and tool usage associated with large-scale phishing, credential theft, account takeover, and business email compromise activity, including payment diversion fraud. Storm-2227 has been observed operating within an ecosystem of criminal services rather than as the attributed operator of RedVDS itself; Microsoft attributes operation of RedVDS to Storm-2470, while Storm-2227 is assessed as a user of that infrastructure. Activity associated with RedVDS-supported actors included deployment of phishing kits and mass-mailing tools, harvesting of credentials and session tokens, unauthorized access to email accounts, and insertion into existing email threads to redirect payments. The broader victimology tied to this infrastructure spans multiple sectors, including real estate, legal, construction, manufacturing, healthcare, logistics, and education, and affected organizations globally. High-confidence characterization supports Storm-2227 as a cybercriminal actor engaged in financially motivated intrusion and fraud operations, with capabilities centered on phishing-enabled initial access, credential and session theft, post-compromise mailbox abuse, and data exfiltration from targeted accounts. Publicly supported facts in this context do not establish a nation-state affiliation, a distinct malware family uniquely tied to the actor, or ransomware/extortion operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Microsoft-tracked activity cluster observed using RedVDS infrastructure in financially motivated phishing/BEC operations.
One of several Microsoft-tracked threat actors leveraging RedVDS-provisioned Windows RDP infrastructure to support phishing/BEC and related fraud operations.
Named Microsoft-tracked threat actor group that leveraged RedVDS virtual Windows servers to support cyber-enabled crime (e.g., phishing, credential theft/account takeover, business email compromise/payment diversion, and related fraud).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.