news.mlab.sh
Back to the feed
threat-intel

Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands

High
Summary

A Russian national, extradited from Cyprus, has been charged with using a network of fake accounts on a freelance platform to spread malware and steal data between 2016 and 2017. The campaign involved distributing malware, including TVRAT and DarkVNC, to approximately 80,000 users, primarily in the U.S., to gain remote access to their computers and steal sensitive information. The DoJ alleges the scheme involved exploiting vulnerabilities in TeamViewer and leveraging fake job postings to lure victims.

The U.S. Department of Justice (DoJ) has charged a Russian national, Searzhudin Tamirlanovich Aktulaev, with using a network of 255 fake accounts on a freelance employment technology company to spread malware and steal data between 2016 and 2017. The DoJ alleges that Aktulaev, arrested in Cyprus in May 2025, orchestrated a campaign targeting approximately 80,000 users, with a significant portion of victims located in the U.S. The scheme relied on fake job postings and the use of a freelance platform to entice victims to open malicious Excel attachments.

These attachments contained malware, including a variant of TVRAT (TeamViewer Remote Access Trojan), also known as TVSPY or TeamSpy, and DarkVNC, a hidden virtual network computing (hVNC) utility. TVRAT exploited a vulnerability in TeamViewer v6, specifically a DLL-hijacking technique, as identified by Kaspersky in 2013. DarkVNC created a concealed desktop on infected machines, allowing operators remote control.

The DoJ notes that the indictment contains allegations only and that Aktulaev is presumed innocent unless and until proven guilty. The development follows similar campaigns by state-sponsored actors, including North Korean hackers using freelance platforms and a Lazarus Group wave leveraging fake job offers with a remote-access backdoor, as documented by ESET and Check Point Research, respectively. The campaign relied on Microsoft’s default VBA macro blocking in Office files obtained from the internet on Windows devices. The DoJ’s investigation is ongoing.

Read the full article at The Hacker News