Malware

Hackers Arrested for Running Services To Bypass Antivirus Software

Recently, two individuals have been arrested by the Romanian police force on Thursday, as these two individuals are being suspected of running three online services that are intended to aid malware development and administration.

The services are being suspected are CyberSeal and Dataprotector crypting and CyberScan; these are generally used to evade antivirus software detection. However, these arrests are part of a joint operation that is covered by the FBI, Europol, Australian, and Norwegian police.

The experts affirmed that these services were acquired by nearly 1560 criminals and are used for crypting by various types of malware, that also includes Remote Access Trojans, Data stealers, and Ransomware. 

Summary in short

Here we have mentioned the summary in short below:-

  • Two administrators were arrested in Romania.
  • Four house searches were conducted out in Bucharest and Craiova.
  • The backend infrastructure is taken down in Romania, Norway, and the United States.

Hackers Bypass Antivirus Software

Antiviruses are quite strong and hard to bypass, but still, the threat actors use a very common method. The hackers can bypass the antivirus through the use of crypters that encrypt or cover the underlying code in a portion of the software. 

Generally, it is malware that are being used to masquerade as something inoffensive until it gets installed on a victim’s computer.

According to the reports, the clients paid US$40 to US$300 for these crypting services, and it also depends on the license conditions. However, all these service ventures were well structured and strived for automatic updates and customer assistance to the clients.

Operational Support of EUROPOL

In this operation, the whole matter is being operated by Europol’s European Cybercrime (EC3). This operation has facilitated the transfer of information and presented forensic, malware, and operational summary for all kinds of action.

In the whole operation, Europol has to allow for the real-time exchange of data between all the countries that are involved in adjusting the operational plan as per the requirement.

The European researchers, along with the FBI, worked mutually to take down the servers that are operating the malware-refining services. After investigating the whole operation, the Romanian police has conducted a search in four houses in Bucharest and Craiova as part of this joint operation.

Apart from this, the investigators have already taken down the servers in Romania, Norway, and the US. On the other side, the cyber-seal.org and cyberscan.org domains used to host two of the services that are now offline.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Also Read:

Vulnerabilities in Popular Antivirus Softwares Let Attackers to Escalate the System Privileges

New SlothfulMedia RAT Hack on Victim Machines to Run Arbitrary Commands, Take Screenshots

Balaji N

BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

1 hour ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

11 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

12 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

12 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

13 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

13 hours ago