Two Romanians Arrested For Running Three Malware Services

cuberseal-ad.png

A part of the CyberSeal ads posted on a hacking forum

Image: ZDNet

Romanian police forces have arrested on Thursday two individuals suspected of running three online services meant to aid malware development and distribution.

The arrests are part of a joint operation that included the FBI, Europol, Australian, and Norwegian police.

Investigators said the two Romanian suspects are believed to be the creators of three services named CyberSeal, DataProtector, and CyberScan.

The first two are so-called "crypter" services. These types of tools allow malware developers to scramble their malware's code to bypass and evade antivirus software.

The third service, called CyberScan, worked as a clone of Google's VirusTotal service. It allowed malware authors to upload and scan their new malware releases and see if it would be detected by antivirus software.

The difference between CyberScan and VirusTotal was that CyberScan didn't share scan results with antivirus vendors, allowing malware authors to test the detectability of their payloads without having to fear that a "detection alert" would be sent back to the antivirus company and trigger an investigation.

The two suspects had been active on the malware scene since at least 2014 when they first began advertising CyberSeal. The two other services were launched in 2015 (DataProtector) and 2019 (CyberScan).

All three were advertised on multiple hacking forums for prices ranging from $40 to $150.

dataprotector-ad.png

An ad for the DataProtector crypter service on a well-known hacking forum

Image: ZDNet
cyberscan-ad.png

An ad promoting the CyberScan service

Image:ZDNet

Europol said the three tools have often been used to crypt and test different types of malware, such as RATs (Remote Access Trojans), information stealers, and ransomware.

More than 1,560 malware authors used the two crypting services to scramble the code of more than 3,000 malware strains.

Authorities cracked down against the gang yesterday, Thursday, November 19, when they searched four locations in the cities of Bucharest and Craiova in Southern Romania and made the two arrests.

According to Romania's Directorate for Investigating Organized Crime and Terrorism (DIICOT), two other persons were also questioned, believed to be part of the group.

Investigators also took down servers in Romania, Norway, and the US. The cyber-seal.org and cyberscan.org domains, used to host two of the services, are now offline.

RECENT NEWS

Reassessing AI Investments: What The Correction In US Megacap Tech Stocks Signals

The recent correction in US megacap tech stocks, including giants like Nvidia, Tesla, Meta, and Alphabet, has sent rippl... Read more

AI Hype Meets Reality: Assessing The Impact Of Stock Declines On Future Tech Investments

Recent declines in the stock prices of major tech companies such as Nvidia, Tesla, Meta, and Alphabet have highlighted a... Read more

Technology Sector Fuels U.S. Economic Growth In Q2

The technology sector played a pivotal role in accelerating America's economic growth in the second quarter of 2024.The ... Read more

Tech Start-Ups Advised To Guard Against Foreign Investment Risks

The US National Counterintelligence and Security Center (NCSC) has advised American tech start-ups to be wary of foreign... Read more

Global IT Outage Threatens To Cost Insurers Billions

Largest disruption since 2017’s NotPetya malware attack highlights vulnerabilities.A recent global IT outage has cause... Read more

Global IT Outage Disrupts Airlines, Financial Services, And Media Groups

On Friday morning, a major IT outage caused widespread disruption across various sectors, including airlines, financial ... Read more