Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
What's Hot

Coinsbee surpasses 5,000 gift card brands and has become the world’s largest crypto gift card platform

Hotel Indigo Leeds will appoint general manager prior to opening

Google Chrome implements distrust and issues over two certificate authorities over compliance

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
Fyself News
Home » US DOJ seizes four domains that support cybercrime crypto services in global operations
Identity

US DOJ seizes four domains that support cybercrime crypto services in global operations

userBy userMay 31, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

May 31, 2025Ravi LakshmananMalware/Cybercrime

The operation of multinational law enforcement agencies has resulted in takedowns of online cybercrime syndicates, providing services to threat actors to prevent malicious software from being detected in security software.

As a result, the US Department of Justice (DOJ) said it had seized four domains and its associated servers promoted cryptographic services on May 27, 2025 in partnership with Dutch and Finnish authorities. These include avcheck[.]Net, encryption[.]biz, and crypto[.]The first person, all will display a seizure notification.

Other countries that participated in this effort include France, Germany, Denmark, Portugal and Ukraine.

“Cryptography is the process of making malware difficult to detect using software,” DOJ said. “Sied Domains provided services to cybercriminals, including counter antivirus (CAV) tools. When used together, CAV and mobile services allow criminals to obfuscate malware, allowing undetectable and unauthorized access to computer systems.”

Cybersecurity

The DOJ said the authorities have made masked purchases to analyze the services and have confirmed that they are being used for cybercrime. In a coordinated announcement, Dutch officials characterized AvCheck as one of the biggest CAV services used by bad actors around the world.

According to the snapshot captured by Internet Archive AvCheck[.]Net was billed as a “fast antivirus scantime checker” and provided the ability for registered users to scan files against 26 antivirus engines, as well as domains and IP addresses with 22 antivirus engines and block lists.

The domain attack was carried out as part of Operation Endgame, an ongoing global effort launched in 2024 to dismantle cybercrime. It marks the fourth major action in recent weeks after the hundreds of domains and servers used by Lumma Stealer, Danabot and various malware families have become confused.

“Cybercriminals don’t just create malware, they’re perfect for maximum destruction,” said a special agent at FBI Houston, who is responsible for Douglas Williams. “By leveraging counter anti-virus services, malicious actors refine their weapons against the world’s toughest security systems, passing through firewalls, circumventing forensic analysis, and wreaking havoc across the victim’s system.”

This development comes as the Esentire Detterment Purecrypter, a malware as a service (MAAS) solution used to distribute information steels such as Lumma and Rhadamanthys using the initial access vectors of ClickFix.

Available for sale at Hackforums[.]For $159 for three months, $399 for a year and $799 for lifetime access by a threat actor named Purecoder, Crypter is distributed using the automated telegram channel @ThePureBot, which also serves as a market for other products, including Pureerat and Purelogs.

Like other providers of such tools, PureCoder must grant a Terms of Use (TOS) agreement that claims that the software is intended for educational purposes only and that violations lead to immediate revocation of access and serial keys.

Cybersecurity

The malware incorporates the ability to patch the NTMANAGEHOTPATCH API into memory on Windows machines running 24H2. The findings show how threat actors can quickly adapt and devise ways to beat new security mechanisms.

“The malware employs the ability to add AMSI bypass, DLL display, anti-VM detection, prevention measures and the recently added Windows 11 24H2 security features via NTMANAGEHOTPATCH API patching,” the Canadian cybersecurity company said.

“Developers use deceptive marketing tactics by promoting “fully undetected” (FUD) status based on AvCheck[.]Net results, Baltotal shows detection through multiple AV/EDR solutions, revealing significant discrepancies in detection rates. ”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleDivided Israel faces internal unrest amid escalating conflict in Gaza | Israeli-Palestinian conflict news
Next Article Truck Accident Unleashes 250 Million Honey Bees in the Northwest US | Environment News
user
  • Website

Related Posts

Google Chrome implements distrust and issues over two certificate authorities over compliance

June 3, 2025

Reduce attribution confusion in Microsoft and CrowdStrike launches shared threat actor glossary

June 3, 2025

The new Chrome Zero Day is actively being used. Google issues emergency out-of-band patches

June 3, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Coinsbee surpasses 5,000 gift card brands and has become the world’s largest crypto gift card platform

Hotel Indigo Leeds will appoint general manager prior to opening

Google Chrome implements distrust and issues over two certificate authorities over compliance

Earthquakes cause mass escape from Pakistan prisons | News

Trending Posts

Earthquakes cause mass escape from Pakistan prisons | News

June 3, 2025

Mount Etna in Italy places spectacular displays when erupting in Sicily | Volcanic News

June 3, 2025

“Pikachu”: Why is Japan fighting against unconventional “slim” names? |Government News

June 3, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Coinsbee surpasses 5,000 gift card brands and has become the world’s largest crypto gift card platform

Top Startups and High-Tech Funding News – June 2, 2025

Elon Musk’s Brain Tech Startup Neuralink raises $650 million in Series E funding

Fisent raises $2 million to advance enterprise-applied Genai process automation

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.