FBI, Secret Service operation takes down AVCheck site used to test malware

AVCheck.net, FBI
(Image credit: Future)

  • The FBI has taken down AVCheck, a site providing services for cybercriminals
  • AVCheck was used to test malware against AV providers without raising alarms
  • Two crypting services were dismantled, as well

AVCheck.net, a website providing analysis services for cybercriminals, has been taken offline as part of a larger law enforcement operation conducted by the FBI, as well as Dutch and Finnish police.

At press time, the website had been defaced and displayed the usual FBI takedown notice: “This domain has been seized in accordance with a seizure warrant issued in the United States District Court for the Southern District of Texas as part of a coordinated law enforcement operation.”

The site operated as a Counter Antivirus (CAV) service, allowing cybercriminals to test their malware against multiple antivirus engines before deploying it, helping them remain undetected during attacks. It was marketed as a "high-speed antivirus scantime checker," and enabled users to scan files, domains, and IP addresses across numerous security tools without alerting antivirus vendors.

Operation Endgame

Matthijs Jaspers, Team Lead of the Dutch High Tech Crime Team, described the takedown as an “important step” in the fight against cybercrime, “because it disrupts the activities of cybercriminals in the earliest stages and prevents victims,” the press release, published on the Dutch police website, stated.

In the same announcement, it was said that the investigation that led to this takedown also yielded “key evidence” on the admins and users of not just AVCheck, but also related services - Cryptor.biz, and Crypt.guru.

These two were ‘crypting services’ that criminals used to "crypt" malware, helping it evade detection.

A separate announcement, published in late May on the DoJ’s site, says the operation resulted “in the seizure of four domains and their associated server,”.

This announcement did not name specific services, but it’s safe to assume it was about these three.

The takedowns are part of Operation Endgame, a large-scale, coordinated international initiative aimed at dismantling cybercriminal infrastructure, particularly focusing on malware and ransomware.

French, German, Ukrainian, and Portuguese law enforcement participated in varying capacities, as well.

Via BleepingComputer

You might also like

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.