Counter AV Service Provider gets 14 Years

Monday, September 24, 2018 @ 04:09 PM gHale

A Latvian man got 14 years in federal prison after being found guilty of his role in operating a counter antivirus service called Scan4You.

Ruslans Bondars, 38, a citizen of the former USSR, and who had been living in Latvia when he was arrested in May 2017 along with Russian national Jurijs Martisevs.

RELATED STORIES
Mirai Authors Avoid Hard Time
Russians Expelled for Swiss Lab Hack Attempt
Nigerian gets 5 Years for Email Scam
Guilty: Botnet Creator Awaits Sentencing

The men were accused of running Scan4You, a service designed to help cybercriminals test their malware to ensure security products would not detect it.

A federal court jury found Bondars guilty in May on one count of conspiracy to violate the Computer Fraud and Abuse Act (CFAA), one count of conspiracy to commit wire fraud, and one count of computer intrusion with intent to cause damage and aiding and abetting.

He has now been sentenced to 14 years in prison, followed by three years of supervised release. The court is also expected to make a decision regarding forfeiture and paying restitution to victims.

This is one of the longest prison sentences handed by a U.S. court for cybercrimes.

Scan4You was active between 2009 and 2016, and it has been described as one of the largest counter AV services. Scan4You allowed cybercriminals to conduct 100,000 scans per month for $30. The service was also popular among counter antivirus resellers such as Indetectables, RazorScanner and reFUD.me

Authorities said the service was used by thousands of users to test malware, including threats that infected tens of millions of devices and ones that helped cybercriminals carry out major operations aimed at U.S. businesses. The court established the losses associated with Scan4You total over $20 billion.

It was not difficult for investigators to identify Bondars. He used the same Gmail account to register command and control (C&C) domains for malware and to create a Facebook account. That Gmail account also contained his real name and profile photo.

Martisevs pleaded guilty in March to conspiracy and aiding and abetting computer intrusions. His sentencing was scheduled for July, but the Justice Department has not provided any updates on the case.



Leave a Reply

You must be logged in to post a comment.