By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: U.S. DoJ Seizes 4 Domains Supporting Cybercrime Crypting Services in Global Operation
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > U.S. DoJ Seizes 4 Domains Supporting Cybercrime Crypting Services in Global Operation
Tech News

U.S. DoJ Seizes 4 Domains Supporting Cybercrime Crypting Services in Global Operation

By Viral Trending Content 4 Min Read
Share
SHARE

May 31, 2025Ravie LakshmananMalware / Cyber Crime

A multinational law enforcement operation has resulted in the takedown of an online cybercrime syndicate that offered services to threat actors to ensure that their malicious software stayed undetected from security software.

To that effect, the U.S. Department of Justice (DoJ) said it seized four domains and their associated server facilitated the crypting service on May 27, 2025, in partnership with Dutch and Finnish authorities. These include AvCheck[.]net, Cryptor[.]biz, and Crypt[.]guru, all of which now display a seizure notice.

Other countries that participated in the effort include France, Germany, Denmark, Portugal, and Ukraine.

“Crypting is the process of using software to make malware difficult for antivirus programs to detect,” the DoJ said. “The seized domains offered services to cybercriminals, including counter-antivirus (CAV) tools. When used together, CAV and crypting services allow criminals to obfuscate malware, making it undetectable and enabling unauthorized access to computer systems.”

Cybersecurity

The DoJ said authorities made undercover purchases to analyze the services and confirmed that they were being used for cybercrime. In a coordinated announcement, Dutch officials characterized AvCheck as one of the largest CAV services used by bad actors around the world.

According to snapshots captured by the Internet Archive, AvCheck[.]net billed itself as a “high-speed antivirus scantime checker,” offering the ability for registered users to scan their files against 26 antivirus engines, as well as domains and IP addresses with 22 antivirus engines and blocklists.

The domain seizures were conducted as part of Operation Endgame, an ongoing global effort launched in 2024 to dismantle cybercrime. It marks the fourth major action in recent weeks after the disruption of Lumma Stealer, DanaBot, and hundreds of domains and servers used by various malware families to deliver ransomware.

“Cybercriminals don’t just create malware; they perfect it for maximum destruction,” said FBI Houston Special Agent in Charge Douglas Williams. “By leveraging counter-antivirus services, malicious actors refine their weapons against the world’s toughest security systems to better slip past firewalls, evade forensic analysis, and wreak havoc across victims’ systems.”

The development comes as eSentire detailed PureCrypter, a malware-as-a-service (MaaS) solution that’s being used to distribute information stealers like Lumma and Rhadamanthys using the ClickFix initial access vector.

Marketed on Hackforums[.]net by a threat actor named PureCoder for $159 for three months, $399 for one year, or $799 for lifetime access, the crypter is distributed using an automated Telegram channel, @ThePureBot, which also serves as a marketplace for other offerings, including PureRAT and PureLogs.

Like other purveyors of such tools, PureCoder requires users to acknowledge a Terms of Service (ToS) agreement that claims the software is meant only for educational purposes and that any violations would result in immediate revocation of their access and serial key.

Cybersecurity

The malware also incorporates the ability to patch the NtManageHotPatch API in memory on Windows machines running 24H2 or newer to re-enable process hollowing-based code injection. The findings demonstrate how threat actors quickly adapt and devise ways to defeat new security mechanisms.

“The malware employs multiple evasion techniques including AMSI bypass, DLL unhooking, anti-VM detection, anti-debugging measures, and recently added capabilities to bypass Windows 11 24H2 security features through NtManageHotPatch API patching,” the Canadian cybersecurity company said.

“The developers use deceptive marketing tactics by promoting ‘Fully UnDetected’ (FUD) status based on AvCheck[.]net results, while VirusTotal shows detection by multiple AV/EDR solutions, revealing significant discrepancies in detection rates.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Sorry Samsung, If Leaks Are True, the Pixel 10 Pro Fold Gets my Vote

How Cloudflare DNS Outage Took Out The Internet

HPE warns of hardcoded passwords in Aruba access points

Best Broadband Deals in Ireland – July 2025

Amazon Web Services latest to cut ‘hundreds’ of jobs amid AI shift

TAGGED: Antivirus, Cyber Security, Cybersecurity, Internet, law enforcement, Malware, Malware-as-a-Service, Operation Endgame, windows security
Share This Article
Facebook Twitter Copy Link
Previous Article Death Stranding 2: On the Beach – Game Premiere Event Announced for June 8th
Next Article Crypto Analyst Calls Massive Bitcoin Crash To $50,000
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Improving Investor Behavior: Don’t just own shares — share ownership
Business
How Bitcoin Is Reacting To The Falling S&P 500 Volatility Index: Expert
Crypto
Embedding human rights into crypto isn’t optional, it’s foundational
Crypto
The 10 Worst Games of 2025 (So Far)
Gaming News
Sorry Samsung, If Leaks Are True, the Pixel 10 Pro Fold Gets my Vote
Tech News
Here’s how a 39-year-old could aim for a million by retirement, by spending £900 a month on UK shares
Business
Corporate actions this week: LIC, Hero Moto and 23 other stocks to set record dates for dividends
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Improving Investor Behavior: Don’t just own shares — share ownership

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Improving Investor Behavior: Don’t just own shares — share ownership
July 20, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?