International law enforcement op shuts down major cybercrime tool AVCheck

International law enforcement op shuts down major cybercrime tool AVCheck

European and American law enforcement agencies have announced the successful takedown of AVCheck, one of the world’s most widely used Counter Antivirus (CAV) services.

AVCheck enabled malware developers to stealthily test their malicious software against commercial antivirus solutions. The takedown, which took place on May 27, was carried out in coordination with law enforcement partners from the United States, the Netherlands, Finland, France, Germany, and Denmark, with operational support from Ukraine and Portugal.

Authorities are now sifting through the seized data to identify and track down users of the illicit service, many of whom are believed to be involved in large-scale ransomware and malware campaigns.

The AVCheck takedown is part of the broader Operation Endgame, launched in May 2024, which targets the infrastructure supporting initial access malware strains such as IcedID, SystemBC, Pikabot, Smokeloader, Bumblebee, and Trickbot. These loaders often serve as the first stage in ransomware attacks, allowing threat actors to gain unauthorized entry into victim networks.

As part of the coordinated crackdown, US authorities also seized four domains linked to AVCheck and associated server infrastructure. These sites provided services to cybercriminals, including both CAV and crypting tools.

An affidavit supporting the seizures revealed that investigators conducted undercover purchases and technical analysis of the services. Additionally, court documents allege that the services were tied to email addresses and other identifiers linked to known ransomware groups that have targeted victims across both the US and Europe.


Back to the list

Latest Posts

Cyber Security Week in Review: June 6, 2025

Cyber Security Week in Review: June 6, 2025

In brief: a critical vBulletin bug is being exploited in the wild, new destructive PathWiper malware targets Ukraine, and more.
6 June 2025
New PathWiper malware targets critical infrastructure in Ukraine

New PathWiper malware targets critical infrastructure in Ukraine

PathWiper shares several characteristics with Sandworm's HermeticWiper, which was used in attacks against Ukraine in 2022.
5 June 2025
US seizes 145 domains linked to BidenCash carding forum

US seizes 145 domains linked to BidenCash carding forum

It is estimated that the operation generated more than $17 million in revenue since launching in March 2022.
5 June 2025