FBI, Secret Service operation takes down AVCheck site used to test malware

2 weeks ago 5
AVCheck.net, FBI
(Image credit: Future)

  • The FBI has taken down AVCheck, a site providing services for cybercriminals
  • AVCheck was used to test malware against AV providers without raising alarms
  • Two crypting services were dismantled, as well

AVCheck.net, a website providing analysis services for cybercriminals, has been taken offline as part of a larger law enforcement operation conducted by the FBI, as well as Dutch and Finnish police.

At press time, the website had been defaced and displayed the usual FBI takedown notice: “This domain has been seized in accordance with a seizure warrant issued in the United States District Court for the Southern District of Texas as part of a coordinated law enforcement operation.”

The site operated as a Counter Antivirus (CAV) service, allowing cybercriminals to test their malware against multiple antivirus engines before deploying it, helping them remain undetected during attacks. It was marketed as a "high-speed antivirus scantime checker," and enabled users to scan files, domains, and IP addresses across numerous security tools without alerting antivirus vendors.

Operation Endgame

Matthijs Jaspers, Team Lead of the Dutch High Tech Crime Team, described the takedown as an “important step” in the fight against cybercrime, “because it disrupts the activities of cybercriminals in the earliest stages and prevents victims,” the press release, published on the Dutch police website, stated.

In the same announcement, it was said that the investigation that led to this takedown also yielded “key evidence” on the admins and users of not just AVCheck, but also related services - Cryptor.biz, and Crypt.guru.

These two were ‘crypting services’ that criminals used to "crypt" malware, helping it evade detection.

A separate announcement, published in late May on the DoJ’s site, says the operation resulted “in the seizure of four domains and their associated server,”.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

This announcement did not name specific services, but it’s safe to assume it was about these three.

The takedowns are part of Operation Endgame, a large-scale, coordinated international initiative aimed at dismantling cybercriminal infrastructure, particularly focusing on malware and ransomware.

French, German, Ukrainian, and Portuguese law enforcement participated in varying capacities, as well.

Via BleepingComputer

You might also like

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read Entire Article