Cyberattack in Hesse: Criminal Infrastructure Shut Down – Limburg Hub

An international law enforcement operation has disrupted the global cybercrime service known as “RedVDS,” with authorities in Germany, the United States, and the United Kingdom collaborating alongside Microsoft to dismantle the infrastructure.

The coordinated action was confirmed by the Central Office for Cybercrime (ZIT) at the Public Prosecutor General’s Office in Frankfurt, and the State Criminal Police Office of Brandenburg in a joint statement released on Wednesday. Investigators estimate hundreds of victims have been impacted.

Authorities and Businesses Among the Victims

German investigators played a key role in the investigation of the platforms. The digital service allowed cybercriminals to commit crimes anonymously, according to the statement from German law enforcement.

Numerous companies and government agencies in Germany, including those in Hesse and Brandenburg, were among those targeted.

Technical Hub of the Criminals Located in Limburg

Suspects have not been apprehended, and are believed to be located in a Middle Eastern country. Experts estimate the financial damage to be in the hundreds of millions of euros.

The technical center of the cybercriminals was a data center located in Germany. According to the German Press Agency (dpa), it was located in Limburg, where RedVDS servers were seized on Tuesday afternoon. Authorities did not disclose the precise location.

Did You Know? The RedVDS service reportedly provided criminals with access to a virtual disposable computer for $24 per month, complete with pirated Windows software.

Millions in Losses from “Boss” Fraud Scheme

The fraud schemes frequently followed a similar pattern: criminals first attempted to gain access to their victims’ computer systems, often through phishing emails.

Once inside, the attackers were able to steal money or sensitive data by impersonating a CEO, colleague, business partner, or supplier, potentially submitting fraudulent invoices or manipulating bank details.

Online Subscription for Criminals

RedVDS allegedly provided these fraudsters with an online subscription service, allowing them to rent the infrastructure needed for their crimes.

According to Microsoft, the service provided access to a virtual disposable computer – a server with pirated Windows software – for $24 a month. This server could be shut down after the crime to hinder prosecution.

Millions of Dangerous Phishing Emails

With the RedVDS subscription, criminals were able to operate quickly, anonymously, and across borders, Microsoft explained. In a single month, more than 2,600 different virtual RedVDS machines sent an average of one million phishing messages per day to Microsoft customers alone.

Although most of these were blocked or flagged, the sheer volume meant that a small percentage may have successfully reached their targets. Victims were not limited to Microsoft customers, but included users of all major platforms.

Expert Insight: The disruption of RedVDS highlights the increasing sophistication of cybercrime-as-a-service models. By providing criminals with readily available infrastructure, these services lower the barrier to entry and enable large-scale attacks. The international cooperation demonstrated in this case is crucial to combating this evolving threat.

Frequently Asked Questions

What was RedVDS?

RedVDS was a cybercrime service that provided criminals with access to infrastructure, including virtual computers and software, for a monthly fee. This allowed them to conduct fraudulent activities anonymously and across borders.

Which countries were involved in dismantling RedVDS?

Germany, the United States, and the United Kingdom collaborated with Microsoft to dismantle the RedVDS infrastructure.

What type of fraud was facilitated by RedVDS?

RedVDS facilitated a “boss” fraud scheme, where criminals impersonated authority figures to steal money or sensitive data from victims, often through phishing emails and fraudulent invoices.

As authorities continue to investigate, it is possible that further details regarding the individuals behind RedVDS will emerge, and additional victims may be identified. It remains to be seen whether this operation will significantly disrupt cybercriminal activity in the long term, or if similar services will emerge to take its place.

Leave a Comment