RedVDS is a cybercrime-as-a-service operation that provides disposable virtual machines used to support large-scale phishing, fraud, and business email compromise activity. The service has been associated with high-volume phishing campaigns and infrastructure that makes criminal operations inexpensive, scalable, and harder to trace. Reported usage includes attacks in which adversaries gain unauthorized access to business email accounts, monitor ongoing conversations, impersonate trusted parties, and redirect payments or invoices at opportune moments. RedVDS has been linked to widespread victimization across multiple sectors, including healthcare, real estate, construction, logistics, and education. It has been used in payment-diversion schemes, including real-estate transaction fraud involving compromised realtor or escrow communications. Reported operational scale includes thousands of virtual machines sending very large volumes of phishing messages daily and fraudulent access affecting a substantial number of organizations worldwide. The actor or service is part of the broader cybercrime subscription-service ecosystem rather than a nation-state intrusion set. Its known alias is redvds_(cybercrime_subscription_service_users_operators). Available reporting supports financially motivated criminal use centered on phishing-enabled fraud and post-compromise abuse of email communications, but does not provide high-confidence attribution to a specific country of origin.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.