Back to blog

Blog Post

Global Law Enforcement Takedown Disrupts Prolific Cybercrime Tool AVCheck

Share on social

Jun 6, 2025

Lorem ipsum

Table of contents

Share on social

Join the newsletter
Global Law Enforcement Takedown Disrupts Prolific Cybercrime Tool AVCheck

[AVCh Cybercrime Tool Takedown]

In this blog series we spotlight one of the stories from our cybersecurity newsletter, Beacon.

In a win for international cybercrime enforcement, European and American authorities have announced the takedown of AVCheck, one of the world’s most prolific Counter Antivirus (CAV) services used by cybercriminals to test their malware against popular antivirus software.

The coordinated operation led by Dutch Politie in cooperation with law enforcement agencies from the US and Finland successfully disrupted a critical enabler of cybercrime activity. By allowing malware authors to ensure their code evaded detection, AVCheck played a key role in facilitating stealthy, effective attacks against individuals and organizations worldwide.

The takedown was announced on Friday May 30th with Dutch officials declaring it an “important step” in the broader fight against cybercrime.

Matthijs Jaspers, team leader at the Dutch National High Tech Crime Unit, said the operation marked an “important step” in the fight against cybercrime.

“This will disrupt cybercriminals as early as possible in their operations and prevent victims. In recent years, the investigation has also collected important evidence about the administrators and users of the AVCheck service and the associated services Cryptor.biz and Crypt.guru,” he added.

A seizure notice posted on the AVCheck platform noted that the takedown was enabled “by exploiting the mistakes of admins,” and revealed that law enforcement officials had seized the service’s servers and user database, including usernames, email addresses, and payment details.

The takedown took place on May 27th and is closely connected to Operation Endgame, a Europol operation to disrupt the infrastructure behind initial access malware families such as IcedID, Smokeloader, Bumblebee, SystemBC, Pikabot, and Trickbot.

“Cybercriminals are difficult to track down. That is why it remains crucial to invest in a broad approach to stay one step ahead of them,” said Jaspers.

“National and international intervention and public-private partnerships are becoming increasingly important – with the aim of combating victims, stopping crimes and preventing online crime from growing. We do not only focus on our traditional task of detection and prosecution, but also on other types of interventions to increase digital security.”

Lizzie Clark
LC

Author

Lizzie Clark

Marketing Executive at Searchlight Cyber

Lizzie is an experienced IT and cybersecurity marketing professional with six years of specialist experience in the industry. Lizzie produces a range of content - from blogs and long-form articles to newsletters and social media - with a focus on writing that informs and engages technical audiences.

Related Blog Posts

August 13, 2026

Phishing and Takedown now managed entirely in Monitor

August 6, 2026

How to Measure Preemptive Threat Exposure Management (PTEM) Success

August 5, 2026

August 4th – This Week’s Top Cybersecurity and Dark Web Stories

July 31, 2026

How Does Preemptive Threat Exposure Management Improve Exposure Prioritization?

July 29, 2026

July 28th – This Week’s Top Cybersecurity and Dark Web Stories

July 24, 2026

Preemptive Threat Exposure Management: Frequently Asked Questions

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient