Two arrested for helping malware developers evade AV software

frogboy

In memoriam 1961-2018
Thread author
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
69,342
7,679
Western Australia
Two suspects have been arrested on suspicion of operating a website offering services to help criminals overcome and avoid anti malware software, following a joint investigation led by the National Crime Agency and Trend Micro.

The suspect’s website - reFUD.me - provided a number of functions, both free and for charge, which allowed malware developers to scan their illegal files. They would then learn whether or not they could successfully infect victims’ computers by circumventing their malware protection.

If a piece of malware was detected, changes could be made by the developer to make the file Fully UnDetectable. Statistics on the website claim that more than 1.2 million scans have been conducted since February 2015.

Crypter services were also offered, allowing malware files to be packaged and disguised using encryption. Cryptex Reborn, the form of crypting available on the forum, is among the most sophisticated developed in recent years.

Malware developers could purchase a licence to download and use the product to encrypt their files – charges ranging from $20 per month to $90 for lifetime usage.

Full article. Two arrested for helping malware developers evade AV software
 
I like how it takes just 2 guys and their software to make malware undetected, looks like anyone with the skill set could do this, arresting them wouldn't have made a huge impact. :P
 
I like how it takes just 2 guys and their software to make malware undetected, looks like anyone with the skill set could do this, arresting them wouldn't have made a huge impact. :p

by crypting them with algorithm evading the AVs
 
I think the logic here, that AV security firms should hire them to improve their capabilities against those undetectable behaviour threats.
 
  • Like
Reactions: Solarquest
Good news!;)
Well, usually the Crypter are purchased in the deep web because, not being public, they have a long "life" before the encrypted malware is detected by the AV.