Historical intelligence backfill. This assessment covers reporting originally published on 2026-01-14 and was added to the RWP archive on 2026-09-07.
RedVDS sold $24 Windows boxes with one cloned hostname — and Microsoft took the storefront to court
Storm-2470's RedVDS marketplace cloned a Windows Server 2022 image (computer name WIN-BUNS25TD77J) into cheap RDP servers that Microsoft says underpinned tens of millions in fraud.
Bottom line up front
CONFIRMED On 14 January 2026 Microsoft published a technical teardown of RedVDS, a criminal marketplace (Storm-2470) selling cheap, unlicensed Windows RDP servers with admin rights and no usage limits — advertised around US $24/month. Every instance Microsoft identified reused one Windows Server 2022 clone with computer name WIN-BUNS25TD77J, a fingerprint in RDP certificates and telemetry. The same day, DCU announced US and (first time) UK legal action. DCU cited roughly $40 million in observed US fraud losses since March 2025, including H2-Pharma (Alabama) losing more than $7.3 million. A later Microsoft story put confirmed losses since 2019 above $66 million.
This is crimeware infrastructure, not a vulnerability in Azure Virtual Desktop. Historical backfill of 14 January 2026 reporting; added 7 September 2026.
What happened
RedVDS was CaaS: buy a disposable Windows box, send BEC, cash out, wipe the disk, get a new IP. Cloning one eval image without changing the machine ID is operational laziness that became a detection gift. DCU's court action aimed at the storefront and the operators, not at every downstream fraudster.
Why it mattered
SOCs still treat "RDP from a cloud VPS" as low-priority noise. A single cloned hostname is a high-precision indicator. The business model — loyalty program, referrals, wipe-and-rotate — is why BEC volume does not need nation-state budgets.
Who / what was affected
Fraud victims globally; Microsoft's named US example is H2-Pharma. Enterprises seeing RDP/BEC from RedVDS hosts. Not an OT story.
Technical context
Hunt: computer name WIN-BUNS25TD77J, matching RDP cert attributes, repeated VPS ASNs with admin RDP. Block inbound RDP from unknown clouds; require phishing-resistant MFA on anything that can move money.
RWP will not republish the shopping-cart UI beyond Microsoft's already-public description.
Exploitation / threat status at the time
CONFIRMED service, clone fingerprint, legal disruption, Microsoft-observed loss figures.
REPORTED true global losses higher than observed.
UNKNOWN how many copycat VDS shops absorbed the customers after takedown.
What defenders should have done
- Detect the hostname/cert fingerprint Microsoft published.
- Treat sudden RDP from bulletproof/VPS ranges as credential-theft follow-on.
- Finance/BEC controls: out-of-band vendor-payment verification.
- Do not confuse this with legitimate AVD; the tell is cloned eval images and crime-shop UX.
RWP assessment
Confidence: High on Microsoft's technical and legal claims as Microsoft-observed.
Defensive actions
- Ingest the hostname IOC; expire it when clones change.
- Payment-fraud tabletop with Treasury.
- Disable unused RDP at the edge.
Sources
- Microsoft Threat Intelligence — Inside RedVDS
- Microsoft Digital Crimes Unit — Microsoft disrupts global cybercrime subscription service
- Microsoft — RedVDS and the invisible infrastructure of modern cybercrime