Russian Hacker Indicted for Using Excel Malware to Target 80,000 Freelancers With TVRAT and DarkVNC

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

A Russian national has been indicted in the United States over an alleged malware operation that targeted roughly 80,000 freelance workers worldwide.

Prosecutors say the campaign used fake accounts and booby-trapped Excel documents to turn ordinary work messages into a route for stealing data and taking control of computers.

The case highlights how familiar office files can still be used to reach large groups of independent workers, who often receive project files from people they do not know.

Between June 2016 and November 2017, the alleged operation sent messages from about 255 fraudulent accounts on an online freelance employment platform.

Analysts at the U.S. Attorney’s Office, Northern District of California, noted that each malicious Excel attachment asked the recipient to enable a macro.

That action allegedly downloaded malware from the internet, showing how a simple prompt could bridge the gap between a convincing message and a serious computer compromise.

The U.S. Attorney’s Office, Northern District of California, said in a report shared with Cyber Security News (CSN) that the alleged campaign relied on TVRAT and DarkVNC, two tools that gave operators a path to view and control infected devices from afar.

The stolen information was sent to command-and-control servers and, prosecutors allege, was later used for fraud and other criminal activity.

Russian Hacker Indicted for Using Excel Malware

A federal grand jury indicted Searzhudin Tamirlanovich Aktulaev, 40, on charges including conspiracy, damaging protected computers, and aggravated identity theft.

Authorities said he was arrested in Cyprus in May 2025, extradited to the United States, and made his first San Francisco court appearance on August 31.

According to the indictment, TVRAT is also known as TVSPY or TeamSpy and allegedly abused a weakness associated with TeamViewer to obtain remote control.

Readers tracking the broader risk around remote-control software can see how attackers abuse TeamViewer access in other intrusions, although this case concerns allegations tied to the earlier TVRAT campaign.

DarkVNC allegedly offered similar remote-control capability through VNC Viewer. The practical lesson is not that every remote-support session is unsafe, but that unexpected requests to open files or allow access deserve close scrutiny.

That remains especially important as new TeamViewer code flaws can create separate security exposure that organisations should patch promptly.

Victims, Stolen Data and Defence

Prosecutors said thousands of infected computers contacted a US-hosted command-and-control domain whose registration was paid with virtual currency.

About half of the alleged victims were in the United States, including many in Northern California. A database recovered from that infrastructure reportedly listed thousands of victims, underlining the campaign’s reach.

Investigators also found a shared document in an email account allegedly used in the activity. It contained e-commerce login credentials and personal information belonging to hundreds of victims.

Similar lures remain effective because files look routine, as reporting on weaponized spreadsheet file attacks has shown in later campaigns.

For freelancers and organisations, the clearest safeguard is to treat unsolicited spreadsheets with caution and never enable macros simply because a message appears work-related.

Verify an unexpected file through a separate trusted channel, limit or block internet-sourced macros where possible, keep remote-access software updated, and watch for unusual outbound connections. These habits also help against phishing attachment delivery tactics that disguise malware as ordinary documents.

Authorities said the investigation involved the Federal Bureau of Investigation, while the Justice Department’s Office of International Affairs secured his extradition on August 28, 2026.

The prosecution is being handled by the National Security, Cyber, and Special Prosecutions Section. The charging document does not identify the freelance platform or publish specific malicious domains, file hashes, or attachment filenames.

Aktulaev remains in federal custody and is scheduled for a status conference on October 5, 2026. The charges are allegations, and he is presumed innocent unless proven guilty. If convicted, he faces penalties that include prison terms and fines across the charged offences.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

The post Russian Hacker Indicted for Using Excel Malware to Target 80,000 Freelancers With TVRAT and DarkVNC appeared first on Cyber Security News.