Tracking & Law Enforcement

Counter Antivirus Service AVCheck Shut Down by Law Enforcement

Counter antivirus services such as AVCheck allow cybercriminals to test whether their malware is detected by antivirus products.

AVCheck seized in takedown operation

Dutch authorities announced the takedown of AVCheck, one of the largest counter antivirus (CAV) services used by cybercriminals worldwide.

CAV services such as AVCheck play an important role in the malware deployment process, as they allow cybercriminals to test if their malware is detected by antivirus products and scanners, before using it in real-world attacks.

Malware that can evade detection can then be deployed without being noticed to steal information, gain and maintain access to compromised systems, and encrypt data or lock down entire enterprise networks.

Cybercriminals often use CAV services in combination with crypting services, which are meant to make the malware more difficult to detect.

AVCheck was taken down on May 27, when authorities seized four domains and their associated server, and set up a fake login page to warn and deter the service’s users.

Law enforcement also seized the service’s database, obtaining email addresses and other data that linked the use of AVCheck to known ransomware groups.

The seizure was performed in coordination with Finnish and Dutch authorities, as part of Operation Endgame, which recently targeted the DanaBot botnet and the Lumma Stealer information stealer.

Advertisement. Scroll to continue reading.

Law enforcement agencies in Denmark, Finland, France, Germany, the Netherlands, and the US participated in the operation, with support from authorities in Portugal and Ukraine.

“By leveraging counter antivirus services, malicious actors refine their weapons against the world’s toughest security systems to better slip past firewalls, evade forensic analysis, and wreak havoc across victims’ systems,” FBI Special Agent Douglas Williams said.

Related: Russian Qakbot Gang Leader Indicted in US

Related: Europol Targets Customers of Smokeloader Pay-Per-Install Botnet

Related: Bumblebee Malware Loader Resurfaces Following Law Enforcement Takedown

Related: Ukrainian Sentenced to Prison in US for Role in Zeus, IcedID Malware Operations

Related Content

Malware & Threats

The shutdown operation involved peer list manipulation and Sality payload URL takedown.

Cybercrime

The defendants unsuccessfully attempted to physically install malware on ATMs to force them to dispense cash.

Data Breaches

The private equity firm appears to have been targeted as part of a campaign focusing on major financial companies.

Malware & Threats

Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands.

Cybercrime

Hundreds of C&C servers were disrupted in an operation involving law enforcement and several cybersecurity companies.

Cybercrime

Nathan Austad has been ordered to pay roughly $1.8 million in forfeiture and restitution, and the sentence also includes 3 years of supervised release. 

Malware & Threats

Mistic is used by Woodgnat, an initial access broker working with Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta.

Cybercrime

26-year-old Abdellah Belmili faces up to 30 years in prison for allegedly operating the marketplaces Market0Day and Spoxy.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version