/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Operator of malware-testing service Scan4You, which helped hackers evade antivirus software, convicted by US jury after Trend Micro gave data to the FBI

MOST ANTIVIRUS SCANNERS play a classic cat and mouse game: They work by checking software against a frequently updated list of potential threats.

Wired Lily Hay Newman

Context & Ripple Effects

The conviction closes out a service that sat at the center of the malware economy: Scan4You let malware authors measure how many antivirus engines flagged their code before deployment, turning evasion into a measurable product feature. The case also surfaced an unusual degree of vendor-law enforcement entanglement — Trend Micro handed data to the FBI that made the prosecution possible.

It lands on an antivirus industry already bruised by integrity questions: ex-employee allegations that Kaspersky tricked rivals' engines into marking legitimate files as false positives, and claims that Cylance used bogus malware samples in sales deals. Detection rates are the industry's core currency, and both the Scan4You case and those episodes show how much rides on who controls testing data.

First-order effects

  • Malware authors lose their main bulk-testing channel for checking code against dozens of engines at once, raising the cost and friction of building undetected payloads.
  • Trend Micro's data-sharing with the FBI sets a precedent inside the vendor community that engine telemetry can be operational evidence, not just internal quality data.

Second-order effects

  • Other antivirus vendors face a choice between similar law enforcement cooperation and customer trust in how their detection data is used — a tension the Kaspersky and Cylance episodes already made raw.
  • Evasion testing migrates deeper underground toward private, invite-only scanning rather than open commercial services, making the remaining operators higher-value targets for the same FBI playbook.

Third-order effects

  • If prosecutions of testing services hold up, the legal boundary around dual-use security tooling hardens: services whose only customers are criminals become prosecutable even when the underlying technology is generic.
  • Antivirus firms drift structurally toward being intelligence suppliers to law enforcement, with detection-rate data becoming an asset whose sharing decisions carry legal and reputational weight.

The trend: The antivirus industry is consolidating into a de facto law-enforcement intelligence layer, as courts criminalize the dual-use testing ecosystem and vendors' own data becomes prosecution evidence.