{"id":35484,"date":"2020-06-12T14:43:10","date_gmt":"2020-06-12T14:43:10","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/31294\/Italian-Company-Exposed-As-A-Front-For-Malware-Operations.html"},"modified":"2020-06-12T14:43:10","modified_gmt":"2020-06-12T14:43:10","slug":"italian-company-exposed-as-a-front-for-malware-operations","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/italian-company-exposed-as-a-front-for-malware-operations\/","title":{"rendered":"Italian Company Exposed As A Front For Malware Operations"},"content":{"rendered":"<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet2.cbsistatic.com\/hub\/i\/2020\/05\/13\/5d58fd08-54ac-461b-a79f-a5904a0b672b\/vulnerability-code-binary.png\" class alt=\"vulnerability code binary\"><\/span><span class=\"credit\">Image: ZDNet<\/span><\/p>\n<p>For the past four years, an Italian company has operated a seemingly legitimate website and business, offering to provide binary protection against reverse engineering for Windows applications, but has secretly advertised and provided its service to malware gangs.<\/p>\n<p>The company&#8217;s secret business came to light after security researchers from Check Point began looking at GuLoader [<a href=\"https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/guloader-popular-new-vb6-downloader-abuses-cloud-services\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">1<\/a>, <a href=\"https:\/\/blog.morphisec.com\/guloader-the-rat-downloader\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">2<\/a>, <a href=\"https:\/\/research.checkpoint.com\/2020\/threat-actors-migrating-to-the-cloud\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">3<\/a>], a new malware strain that rose to become one of the most active malware operations of 2020.<\/p>\n<h3>CloudEyE app linked to defunct malware crypter DarkEyE<\/h3>\n<p>Check Point says it found references in the GuLoader code mentioning CloudEyE Protector, an anti-reverse-engineering software service provided by an Italian company named CloudEyE.<\/p>\n<p>But while source code protection services are legal and widely used, almost by all commercial\/legitimate apps, Check Point said it linked this company and its owners to activity on hacking forums going back years.<\/p>\n<p>The cyber-security firm connected the CloudEyE binary protecting service advertised on the securitycode.eu website to ads promoting a malware crypting service named DarkEyE, heavily advertised on hacking forums as far back as 2014.<\/p>\n<p>Furthermore, Check Point also linked three usernames and emails used to promote DarkEyE to the real-world identity of one of the CloudEyE founders, as displayed on the CloudEyE website.<\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/italian-company-exposed-as-a-front-for-malware-operations\/\" class=\"lazy\" alt=\"cloudeye-identities.png\" data-original=\"https:\/\/zdnet4.cbsistatic.com\/hub\/i\/2020\/06\/12\/ea931850-10f2-4bb6-8763-1585497a7782\/cloudeye-identities.png\"><\/span><noscript><\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet4.cbsistatic.com\/hub\/i\/2020\/06\/12\/ea931850-10f2-4bb6-8763-1585497a7782\/cloudeye-identities.png\" class alt=\"cloudeye-identities.png\"><\/span><\/p>\n<p><\/noscript> <span class=\"credit\">Image: Check Point<\/span><\/p>\n<p>In addition, Check Point says it also tracked these three email addresses and usernames to multiple posts on hacking forums.<\/p>\n<section class=\"sharethrough-top\" data-component=\"medusaContentRecommendation\" data-medusa-content-recommendation-options=\"{&quot;promo&quot;:&quot;promo_zd_recommendation_sharethrough_top_in_article_desktop&quot;,&quot;spot&quot;:&quot;dfp-in-article&quot;}\">\n<\/section>\n<p>The posts advertised malware\/binary crypting services even before DarkEyE (CloudEyE&#8217;s precursor), and went as far back as 2011, showing how entrenched and well-connected this user was in the cybercrime and malware community.<\/p>\n<h3>CloudEyE made at least $500,000<\/h3>\n<p>These connections apparently helped the group get their legitimate business off the ground. Check Point says the CloudEyE team bragged of having more than 5,000 customers on their website.<\/p>\n<p>Based on their minimum rate of $100\/month, Check Point says the group earned at least $500,000 from their service. However, the sum could be much higher if we take into account that some monthly plans can go up to $750\/month, and some customers most likely used the service multiple months.<\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/italian-company-exposed-as-a-front-for-malware-operations\/\" class=\"lazy\" alt=\"cloudeye-site.png\" height=\"auto\" width=\"470\" data-original=\"https:\/\/zdnet1.cbsistatic.com\/hub\/i\/r\/2020\/06\/12\/e0675998-1c5b-4667-8407-f7039bb4b7d0\/resize\/470xauto\/e219953e7df14066e2772cf9403c8d01\/cloudeye-site.png\"><\/span><noscript><\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet1.cbsistatic.com\/hub\/i\/r\/2020\/06\/12\/e0675998-1c5b-4667-8407-f7039bb4b7d0\/resize\/470xauto\/e219953e7df14066e2772cf9403c8d01\/cloudeye-site.png\" class alt=\"cloudeye-site.png\" height=\"auto\" width=\"470\"><\/span><\/p>\n<p><\/noscript> <span class=\"credit\">Image: ZDNet<\/span><\/p>\n<p>All clues point to the fact that the two CloudEyE operators attempted to legitimize their criminal operation by hiding it behind a front company as a way to justify their profits and avoid raising the suspicions of local tax authorities when cashing out their massive profits.<\/p>\n<p>&#8220;CloudEyE operations may look legal, but the service provided by CloudEyE has been a common denominator in thousands of attacks over the past year,&#8221; Check Point said.<\/p>\n<h3>GuLoader was the main customer<\/h3>\n<p>But while Check Point says the DarkEyE and CloudEyE tools were widely used over the past years, there is one malware operation that appears to be CloudEye&#8217;s primary customer, and that&#8217;s GuLoader.<\/p>\n<p>In a <a href=\"https:\/\/research.checkpoint.com\/2020\/guloader-cloudeye\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">report published this week<\/a>, Check Point lays out the different connections between CloudEyE and GuLoader.<\/p>\n<p>The most obvious is that the code of apps passed through the CloudEyE Protect app contained similar patterns with GuLoader malware samples spotted in the wild. This connection was so strong that any random app passed through the CloudEyE app would almost certainly be detected as a GuLoader malware sample, despite being a legitimate app.<\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/italian-company-exposed-as-a-front-for-malware-operations\/\" class=\"lazy\" alt=\"cloudeye-samples.png\" data-original=\"https:\/\/zdnet2.cbsistatic.com\/hub\/i\/2020\/06\/12\/f635e565-7330-49f7-a767-61ff0825233d\/cloudeye-samples.png\"><\/span><noscript><\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet2.cbsistatic.com\/hub\/i\/2020\/06\/12\/f635e565-7330-49f7-a767-61ff0825233d\/cloudeye-samples.png\" class alt=\"cloudeye-samples.png\"><\/span><\/p>\n<p><\/noscript> <span class=\"credit\">Image: Check Point<\/span><\/p>\n<p>Second, Check Point says that the CloudEyE interface contained a placeholder (default) URL that it often found in GuLoader samples.<\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/italian-company-exposed-as-a-front-for-malware-operations\/\" class=\"lazy\" alt=\"cloudeye.png\" data-original=\"https:\/\/zdnet2.cbsistatic.com\/hub\/i\/2020\/06\/12\/4c7a53c7-f452-4cfd-94e9-eba8dc426678\/cloudeye.png\"><\/span><noscript><\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet2.cbsistatic.com\/hub\/i\/2020\/06\/12\/4c7a53c7-f452-4cfd-94e9-eba8dc426678\/cloudeye.png\" class alt=\"cloudeye.png\"><\/span><\/p>\n<p><\/noscript> <span class=\"credit\">Image: Check Point<\/span><\/p>\n<p>Third, many of the CloudEyE features appear to have been specifically designed to support GuLoader operations.<\/p>\n<p>&#8220;Tutorials published on the CloudEyE website show how to store payloads on cloud drives such as Google Drive and OneDrive,&#8221; Check Point said.<\/p>\n<p>&#8220;Cloud drives usually perform anti-virus checking and technically don&#8217;t allow the upload of malware. However, payload encryption implemented in CloudEyE helps to bypass this limitation.&#8221;<\/p>\n<p>Such a feature makes no sense for a normal app. However, avoiding cloud scans is crucial for a malware operation, and especially for something like GuLoader &#8212; categorized as a &#8220;network downloader &#8212; which relies on infecting a victim computer and then downloading a second-stage payload from services such as Google Drive or Microsoft OneDrive.<\/p>\n<h3>CloudEyE shuts down after report<\/h3>\n<p>Following Check Point&#8217;s damning report on Monday, CloudEyE has responded to the findings on Wednesday.<\/p>\n<p>The Italian company denounced the report and blamed the tool&#8217;s use for malware operations on abuses perpetrated by its users, without its knowledge.<\/p>\n<p>However, members of the cyber-security community dismissed the company&#8217;s statement as &#8220;poor lies&#8221; and have called on Italian authorities to investigate the company and its two founders.<\/p>\n<p>Based on Check Point&#8217;s report, the two are at risk of being investigated under charges of aiding and abetting a criminal operation and money laundering.<\/p>\n<p> READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/31294\/Italian-Company-Exposed-As-A-Front-For-Malware-Operations.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":35485,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[8706],"class_list":["post-35484","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlinemalwareitaly"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Italian Company Exposed As A Front For Malware Operations 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/italian-company-exposed-as-a-front-for-malware-operations\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Italian Company Exposed As A Front For Malware Operations 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/italian-company-exposed-as-a-front-for-malware-operations\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2020-06-12T14:43:10+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/06\/italian-company-exposed-as-a-front-for-malware-operations.png\" \/>\n\t<meta property=\"og:image:width\" content=\"863\" \/>\n\t<meta property=\"og:image:height\" content=\"400\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/italian-company-exposed-as-a-front-for-malware-operations\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/italian-company-exposed-as-a-front-for-malware-operations\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Italian Company Exposed As A Front For Malware Operations\",\"datePublished\":\"2020-06-12T14:43:10+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/italian-company-exposed-as-a-front-for-malware-operations\\\/\"},\"wordCount\":783,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/italian-company-exposed-as-a-front-for-malware-operations\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/06\\\/italian-company-exposed-as-a-front-for-malware-operations.png\",\"keywords\":[\"headline,malware,italy\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/italian-company-exposed-as-a-front-for-malware-operations\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/italian-company-exposed-as-a-front-for-malware-operations\\\/\",\"name\":\"Italian Company Exposed As A Front For Malware Operations 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/italian-company-exposed-as-a-front-for-malware-operations\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/italian-company-exposed-as-a-front-for-malware-operations\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/06\\\/italian-company-exposed-as-a-front-for-malware-operations.png\",\"datePublished\":\"2020-06-12T14:43:10+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/italian-company-exposed-as-a-front-for-malware-operations\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/italian-company-exposed-as-a-front-for-malware-operations\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/italian-company-exposed-as-a-front-for-malware-operations\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/06\\\/italian-company-exposed-as-a-front-for-malware-operations.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/06\\\/italian-company-exposed-as-a-front-for-malware-operations.png\",\"width\":863,\"height\":400},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/italian-company-exposed-as-a-front-for-malware-operations\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,malware,italy\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinemalwareitaly\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Italian Company Exposed As A Front For Malware Operations\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Italian Company Exposed As A Front For Malware Operations 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/italian-company-exposed-as-a-front-for-malware-operations\/","og_locale":"en_US","og_type":"article","og_title":"Italian Company Exposed As A Front For Malware Operations 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/italian-company-exposed-as-a-front-for-malware-operations\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2020-06-12T14:43:10+00:00","og_image":[{"width":863,"height":400,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/06\/italian-company-exposed-as-a-front-for-malware-operations.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/italian-company-exposed-as-a-front-for-malware-operations\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/italian-company-exposed-as-a-front-for-malware-operations\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Italian Company Exposed As A Front For Malware Operations","datePublished":"2020-06-12T14:43:10+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/italian-company-exposed-as-a-front-for-malware-operations\/"},"wordCount":783,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/italian-company-exposed-as-a-front-for-malware-operations\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/06\/italian-company-exposed-as-a-front-for-malware-operations.png","keywords":["headline,malware,italy"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/italian-company-exposed-as-a-front-for-malware-operations\/","url":"https:\/\/www.threatshub.org\/blog\/italian-company-exposed-as-a-front-for-malware-operations\/","name":"Italian Company Exposed As A Front For Malware Operations 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/italian-company-exposed-as-a-front-for-malware-operations\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/italian-company-exposed-as-a-front-for-malware-operations\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/06\/italian-company-exposed-as-a-front-for-malware-operations.png","datePublished":"2020-06-12T14:43:10+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/italian-company-exposed-as-a-front-for-malware-operations\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/italian-company-exposed-as-a-front-for-malware-operations\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/italian-company-exposed-as-a-front-for-malware-operations\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/06\/italian-company-exposed-as-a-front-for-malware-operations.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/06\/italian-company-exposed-as-a-front-for-malware-operations.png","width":863,"height":400},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/italian-company-exposed-as-a-front-for-malware-operations\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,malware,italy","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinemalwareitaly\/"},{"@type":"ListItem","position":3,"name":"Italian Company Exposed As A Front For Malware Operations"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/35484","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=35484"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/35484\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/35485"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=35484"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=35484"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=35484"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}