A Russian citizen has been indicted in the United States for allegedly orchestrating a large-scale malware campaign that compromised approximately 80,000 freelance workers worldwide. According to prosecutors, the operation relied on fraudulent accounts and weaponized Microsoft Excel documents to infect victims' computers, steal sensitive information, and gain remote access to compromised systems. The case serves as a reminder that seemingly routine office documents remain an effective vehicle for cybercriminals targeting remote workers and freelancers who frequently exchange project files with unfamiliar clients.
Between June 2016 and November 2017, the attackers allegedly used roughly 255 fake accounts on a popular freelance marketplace to distribute malicious Excel attachments disguised as legitimate work-related documents. Investigators from the U.S. Attorney's Office for the Northern District of California said the spreadsheets prompted recipients to enable macros. Once activated, the macros downloaded malware from external infrastructure, transforming an ordinary project request into a full-scale device compromise. In information shared with Cyber Security News (CSN), authorities said the campaign deployed TVRAT and DarkVNC, two remote-access tools that enabled operators to monitor and control infected computers from afar. Prosecutors allege that stolen information was transmitted to command-and-control (C2) servers and later used in fraud schemes and other criminal activities.
Indictment Linked to TVRAT and DarkVNC Malware
A federal grand jury indicted Searzhudin Tamirlanovich Aktulaev, 40, on charges including conspiracy, intentional damage to protected computers, and aggravated identity theft. Authorities stated that Aktulaev was arrested in Cyprus in May 2025, extradited to the United States, and appeared in federal court in San Francisco on August 31. According to the indictment, TVRAT, also known as TVSPY or TeamSpy, allegedly exploited functionality associated with TeamViewer to establish unauthorized remote access to victim systems.
DarkVNC, meanwhile, reportedly provided similar capabilities through VNC technology, allowing attackers to remotely interact with compromised devices, execute commands, and harvest information. While the case centers on these specific malware families, investigators noted that the broader lesson is the importance of treating unsolicited attachments and unexpected file-sharing requests with caution, especially when they require enabling macros or granting elevated permissions.
Thousands of Victims Worldwide
Prosecutors said thousands of infected systems connected to a command-and-control server hosted in the United States, with domain registration costs allegedly paid using cryptocurrency. Approximately half of the identified victims were located in the United States, including a significant number in Northern California. Investigators also recovered a database from the malware infrastructure that reportedly contained records for thousands of compromised users, highlighting the campaign's extensive reach. Authorities further uncovered a shared document stored within an email account allegedly linked to the operation. The document reportedly contained e-commerce account credentials and personal information belonging to hundreds of victims. The campaign demonstrated how cybercriminals continue to exploit trusted business workflows, disguising malware as legitimate project documentation to increase the likelihood of infection.
Security Recommendations
Security experts advise freelancers, contractors, and organizations to take extra precautions when handling files received from unknown or unverified sources.
Recommended defenses include:
- Avoid enabling macros in unsolicited Office documents.
- Verify unexpected file requests through a separate trusted communication channel.
- Restrict or disable internet-sourced macros whenever possible.
- Keep remote-access and collaboration software fully updated.
- Monitor systems for suspicious outbound network connections.
- Implement endpoint detection and anti-malware protections.
- Provide security awareness training for employees and contractors.
These measures can significantly reduce the risk posed by phishing campaigns and malware delivered through malicious attachments.
Investigation and Legal Proceedings
The investigation was led by the Federal Bureau of Investigation (FBI), while the Department of Justice's Office of International Affairs coordinated the extradition process, which was completed on August 28, 2026. The case is being prosecuted by the National Security, Cyber, and Special Prosecutions Section. Authorities have not publicly disclosed the name of the freelance platform involved, nor have they released the malicious domains, file hashes, or attachment names referenced in the investigation.
Aktulaev remains in federal custody and is scheduled to appear for a status conference on October 5, 2026. As with all criminal proceedings, the charges contained in the indictment are allegations. The defendant is presumed innocent unless and until proven guilty in court. If convicted, Aktulaev could face substantial prison sentences and financial penalties related to the charged offenses.
Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post.
