Dutch authorities arrested a 33-year-old Dutch man suspected of operating AVCheck, a major “counter-antivirus” service used by cybercriminals to test malware against multiple antivirus engines and tune payloads to evade detection. The suspect was detained at Schiphol Airport in Amsterdam after an international surveillance effort; investigators seized data storage devices and are also examining the role of two companies allegedly tied to enabling access to the platform.
AVCheck was previously taken down as part of Operation Endgame, a multinational disruption effort coordinated by authorities in the Netherlands, the United States, and Finland. Prosecutors said the suspect deregistered in the Netherlands and reportedly fled to the United Arab Emirates around the time of the platform’s takedown, and that intelligence gathered during the earlier operation contributed to identifying and investigating him.

See the reporting duties and controls this puts on the clock.
4 events from the most recent confirmed update back to the earliest known activity.
Dutch authorities publicly announced the arrest of the suspected AVCheck operator and said the case was built in part using intelligence obtained from the 2025 takedown. Officials alleged the suspect and two associated companies enabled cybercriminals and malware developers to use the platform.
Dutch authorities arrested a 33-year-old Dutch man suspected of being behind AVCheck on Sunday evening at Schiphol Airport in Amsterdam after an international surveillance operation. Officials also seized the suspect's data storage devices.
Around the time AVCheck was dismantled, the suspected operator reportedly deregistered in the Netherlands and fled to the United Arab Emirates. Prosecutors cited this movement as part of the case timeline tied to the service's shutdown.
AVCheck, a major counter-antivirus service used by cybercriminals to test malware against antivirus products, was taken down during the second wave of Operation Endgame in a coordinated action by authorities in the Netherlands, the United States, and Finland. Investigators later said intelligence gathered from this disruption helped identify the suspected operator.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.