/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Operator of malware-testing service Scan4You, which helped hackers evade antivirus software, convicted by US jury after Trend Micro gave data to the FBI

Lily Hay Newman / Wired :

Wired Lily Hay Newman

Context & Ripple Effects

The conviction closes the loop on a service that sat at the center of the malware economy: Scan4You let malware authors check their code's detection rates across antivirus engines before deployment, turning evasion from guesswork into a paid QA step. Its operator was convicted by a US jury after Trend Micro supplied data to the FBI.

The verdict lands in an industry whose own testing practices were already under scrutiny — Reuters reported ex-employees alleging Kaspersky tricked rivals' engines into flagging false positives, and Ars Technica covered Cylance's alleged use of bogus malware to close deals. What changed here is directionality: instead of vendors fighting each other over detection claims, one vendor armed prosecutors against the evasion economy itself.

First-order effects

  • Malware authors lose their cheapest feedback mechanism — a single service that measured detection rates across many engines at once — raising the cost and uncertainty of shipping evasive code.
  • Trend Micro becomes the named vendor that crossed from defense into prosecution support, setting its relationship with law enforcement apart from peers.

Second-order effects

  • Other antivirus vendors face implicit pressure to share engine data with investigators, since the conviction demonstrates that cooperation produces convictions while non-cooperation leaves them exposed to the same evasion traffic.
  • Underground testing migrates toward closed, invitation-only channels away from monitored commercial services, fragmenting the market Scan4You consolidated.

Third-order effects

  • Criminal liability extends beyond malware authors to the services and infrastructure that support them, giving US prosecutors a template for charging the malware economy's supply chain rather than only its end products.
  • The boundary between commercial threat intelligence and law-enforcement evidence hardens: if the pattern holds, vendor telemetry becomes a routine prosecutorial input, reshaping what vendors collect, retain, and can be compelled to hand over.

The trend: Antivirus vendors are evolving from passive defenders into active evidentiary partners in prosecutions targeting the malware-support economy, with the Scan4You case as an early template.