Cyber News / Article / Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands

Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands
The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in 2016 and 2017.
Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025, the U.S. Attorney's Office for the Northern District of California said in a press release. He made his initial appearance in federal court in San Francisco on August 31 and was remanded to federal custody.
The indictment, filed on June 1, 2021, and unsealed the same day as his appearance, describes the platform only as "a well-known freelance employment technology company" based in the Northern District of California.
Thousands of computers infected withTVRAT, one of two malware types named in the indictment, were calling back to a command-and-control (C2) domain hosted in the U.S., with approximately half of the victims located in the country, many of them in the district.
A shared document in the email account used in the scheme contained e-commerce login credentials and personally identifiable information (PII) for hundreds of victims.
Aktulaev is charged with conspiracy to commit wire fraud; transmission of a program, information, code, or command to cause damage to protected computers; conspiracy to commit computer fraud; unauthorized access to a protected computer to obtain information for financial gain and to obtain value; and aggravated identity theft.
The indictment alleges that from at least June 2016 through November 2017, the messages carried Excel attachments that prompted recipients to run a macro. The macro then downloaded malware from the internet.
The malware came in two types:
Both sent stolen data to the C2 server, from which it was collected and used by Aktulaev and his co-conspirators to commit fraud or other criminal activity, the DoJ said.
The DoJ's releasesays TVRAT exploits a vulnerability in TeamViewer. Russian cybersecurity vendor Kaspersky used the same term in itsMarch 2013 report on TeamSpy, stating that the malicious module "uses a vulnerability in TeamViewer v6 known as Dll-hijacking."
"We have no evidence to assume a vulnerability of our software," a TeamViewer spokesman told Security Affairs in February 2017.
Avast, whichanalyzed a TeamSpy samplespread via Excel macros in April 2017, said the macro fetched a password-protected installer that bundles legitimate, digitally signed TeamViewer binaries with a malicious msimg32.dll.
The library is loaded in place of the genuine Windows dynamic-link library (DLL) via DLL search order hijacking, which Avast said is "a clever technique" because checking the main executable's signature reveals nothing suspicious.
Once loaded, the library hooks nearly 50 Windows Application Programming Interfaces (APIs) to prevent the TeamViewer window and its dialogs from being displayed to the victim. The infected machine then reports its TeamViewer ID to a C2 server. That ID, together with a preset password, is enough for the operators to connect to the computer remotely, Avast said.
DarkVNC, for its part, is a hidden virtual network computing (hVNC) utility that was first advertised on the Exploit forum on November 24, 2016, eSentire said ina February 2024 analysis.
The tool creates a concealed desktop on the infected machine for the operator to control. Microsoft has blocked Visual Basic for Applications (VBA)macros by default since 2022in Office filesobtained from the interneton Windows devices, the delivery step this campaign relied on.
Aktulaev has denied guilt and said he was unaware of the U.S. charges, according to statements from the Russian Embassy in Nicosia, as reported by RIA Novosti and TASS earlier this year.
The DoJ noted that the indictment contains allegations only and that Aktulaev is presumed innocent unless and until proven guilty.
The development comes as job-hunting and freelancing sites remain a recurring lure for state-sponsored actors, with ESET saying in February 2025 that North Korean hackers were usingthe same freelance-platform lureagainst software developers.
Last month, fake-recruiter campaigns were documented by Check Point Research, which saida Lazarus Group wavepaired fake job offerswith a remote-access backdoor, and by the Computer Emergency Response Team of Ukraine (CERT-UA), which saida Sandworm-linked clusterwascontacting candidates through job-site chatbefore pushing a virtual private network (VPN) client that can run commands.
Related articles
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
4 days ago
Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel
6 days ago
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
7 days ago

