Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Tracking & Law Enforcement

Counter Antivirus Service AVCheck Shut Down by Law Enforcement

Counter antivirus services such as AVCheck allow cybercriminals to test whether their malware is detected by antivirus products.

AVCheck seized in takedown operation

Dutch authorities announced the takedown of AVCheck, one of the largest counter antivirus (CAV) services used by cybercriminals worldwide.

CAV services such as AVCheck play an important role in the malware deployment process, as they allow cybercriminals to test if their malware is detected by antivirus products and scanners, before using it in real-world attacks.

Malware that can evade detection can then be deployed without being noticed to steal information, gain and maintain access to compromised systems, and encrypt data or lock down entire enterprise networks.

Cybercriminals often use CAV services in combination with crypting services, which are meant to make the malware more difficult to detect.

AVCheck was taken down on May 27, when authorities seized four domains and their associated server, and set up a fake login page to warn and deter the service’s users.

Law enforcement also seized the service’s database, obtaining email addresses and other data that linked the use of AVCheck to known ransomware groups.

The seizure was performed in coordination with Finnish and Dutch authorities, as part of Operation Endgame, which recently targeted the DanaBot botnet and the Lumma Stealer information stealer.

Advertisement. Scroll to continue reading.

Law enforcement agencies in Denmark, Finland, France, Germany, the Netherlands, and the US participated in the operation, with support from authorities in Portugal and Ukraine.

“By leveraging counter antivirus services, malicious actors refine their weapons against the world’s toughest security systems to better slip past firewalls, evade forensic analysis, and wreak havoc across victims’ systems,” FBI Special Agent Douglas Williams said.

Related: Russian Qakbot Gang Leader Indicted in US

Related: Europol Targets Customers of Smokeloader Pay-Per-Install Botnet

Related: Bumblebee Malware Loader Resurfaces Following Law Enforcement Takedown

Related: Ukrainian Sentenced to Prison in US for Role in Zeus, IcedID Malware Operations

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Barry Childe has joined data sciences tech company Datavault AI as Chief Information Security Officer.

John DeSimone, the former CEO of Nightwing, has been named Chief Operating Officer at Everfox.

Sectigo has appointed Prem Hareesh as Corporate Chief Technology Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.