Excel Malware Extraditee Faces Fresh Charges
Russian national Searzhudin Aktulaev faces U.S. charges over Excel malware that infected thousands via a freelance platform.
Nearly a decade after a campaign that allegedly spread malware through Excel attachments to tens of thousands of users of a major freelance platform, the U.S. Department of Justice has unsealed charges against a Russian national arrested in Cyprus. The case, which became public on August 31, marks a rare extradition for a cybercrime suspect and highlights a lure that remains popular among threat actors.
The arrest and extradition
Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025 and extradited to the U.S. on August 28. He made his initial appearance in federal court in San Francisco on August 31 and was ordered into federal custody. The indictment against him was filed on June 1, 2021, and unsealed the same day as his court appearance.
The U.S. Attorney's Office for the Northern District of California, which brought the case, said Aktulaev is accused of using roughly 255 fake accounts on a freelance employment platform to send malicious emails to about 80,000 of its users during 2016 and 2017. The indictment describes the platform only as a "well-known freelance employment technology company" based in the Northern District of California.
The lure: a malicious Excel macro
According to the indictment, the emails carried Excel attachments that prompted recipients to enable a macro. When run, the macro downloaded malware from the internet onto the victim's computer. This technique—delivering malware through macros in documents—is an old but still effective social engineering method, especially when the email appears to come from a legitimate source like a job platform.
The freelance platform context is significant because job seekers are often eager to open attachments from potential employers, making them more susceptible to such tricks.
Two malware families
The indictment names two types of malware used in the campaign: a variant of TVRAT, a TeamViewer remote access trojan also known as TVSPY or TeamSpy, and DarkVNC. Both gave operators remote control over infected computers and were used to steal data.
TVRAT is a well-known threat that has been documented for years. Russian cybersecurity vendor Kaspersky, in its March 2013 report on TeamSpy, stated that the malicious module "uses a vulnerability in TeamViewer v6 known as Dll-hijacking."
"We have no evidence to assume a vulnerability of our software,"
— a TeamViewer spokesman told Security Affairs in February 2017.
Avast, which analyzed a TeamSpy sample spread via Excel macros in April 2017, said the macro fetched a password-protected installer carrying legitimate, digitally signed TeamViewer binaries alongside a malicious msimg32.dll. By using a DLL search order hijacking technique, the malicious library is loaded in place of the genuine Windows DLL, making the main executable appear legitimate.
Avast called this approach "a clever technique" because checking the main executable's signature reveals nothing suspicious. Once loaded, the library hooks nearly 50 Windows APIs to hide the TeamViewer window and dialogs from the victim. The infected machine then reports its TeamViewer ID to a command-and-control (C2) server, giving operators a way to connect remotely using that ID and a preset password.
DarkVNC, on the other hand, is a hidden virtual network computing (hVNC) utility that eSentire said was first advertised on the Exploit forum on November 24, 2016, in its February 2024 analysis. This tool creates a concealed desktop on the infected machine, allowing the operator to control it without the victim noticing.
Who was affected
The DoJ reported that thousands of computers infected with TVRAT, one of the two malware types, were calling back to a C2 domain hosted in the U.S. Approximately half of the victims were located in the country, many of them within the Northern District of California.
The email account used in the scheme contained a shared document with e-commerce login credentials and personally identifiable information (PII) for hundreds of victims, indicating the attackers were collecting data for financial fraud.
The stolen data was sent to the C2 server, where Aktulaev and his co-conspirators allegedly collected it and used it to commit fraud or other criminal activity, according to the DoJ.
The charges
Aktulaev faces several charges, including:
- Conspiracy to commit wire fraud
- Transmission of a program, information, code, or command to cause damage to protected computers
- Conspiracy to commit computer fraud
- Unauthorized access to a protected computer to obtain information for financial gain and to obtain value
- Aggravated identity theft
The indictment alleges that the malicious activity occurred from at least June 2016 through November 2017.
Aktulaev's denial
According to statements from the Russian Embassy in Nicosia, as reported by RIA Novosti and TASS, Aktulaev has denied guilt and said he was unaware of the U.S. charges. These statements were made earlier this year, before his extradition.
The DoJ noted that the indictment contains allegations and that Aktulaev is presumed innocent unless and until proven guilty.
Macros: exploits to defenses
This campaign relied on VBA macros in Office files, a technique that has become harder to execute as security has improved. Microsoft has blocked Visual Basic for Applications (VBA) macros by default since 2022 in Office files obtained from the internet on Windows devices. That change directly targets the delivery step this campaign depended on.
Despite such defensive improvements, macro-based attacks remain a concern, especially when users are tricked into enabling content in attachments that appear to come from trusted sources like job recruiters.
The rise of similar lures
The use of freelance platforms as a lure has become a recurring theme in recent cybercrime reporting. ESET said in February 2025 that North Korean hackers were using the same freelance-platform lure against software developers.
Last month, Check Point Research documented a Lazarus Group wave that paired fake job offers with a remote-access backdoor, and CERT-UA said a Sandworm-linked cluster was contacting candidates through job-site chat before pushing a VPN client that can run commands.
These examples show that threat actors continue to exploit the trust job seekers place in online hiring platforms, just as Aktulaev allegedly did years earlier.
Why it matters
The scale of this operation—tens of thousands of emails, hundreds of victims' data stolen—shows how a single actor can exploit trust in online hiring spaces. While the techniques here are not new, the case underscores the persistent threat these platforms face and the importance of user vigilance when handling unsolicited attachments.
The outcome of this case could also signal how law enforcement and tech companies collaborate to deter such schemes across borders, particularly as extradition becomes a more common tool for cybercrime cases.
Sources
- The Hacker News Original source
Continue Reading
Freelancer phishing campaign nets 80,000 infections
US indicts Russian national accused of using phishing emails to spread TVRAT and DarkVNC malware to freelancers.
Two-Decade Botnet Finally Falls
Global joint operation seizes Sality infrastructure, dismantling a botnet active since 2003.
US seizes Chinese state hacking infrastructure
FBI and DOJ dismantle QTFY's shared hacking platforms, exposing China's marketized cyber operations.