Russian Hacker Extradited Over Excel Macro Campaign That Hit 80,000 Freelance Platform Users
A Russian national has been extradited from Cyprus to face federal charges in the US over a malware campaign that targeted tens of thousands of users on a major freelance employment platform back in 2016 and 2017.
Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025 and appeared before a federal court in San Francisco on August 31, where he was remanded into custody. The indictment itself was filed back in June 2021 but remained sealed until his court appearance.
According to the DoJ, Aktulaev used around 255 fake accounts on the unnamed platform to blast out malware-laden Excel files to roughly 80,000 users. The platform is described only as a well-known freelance tech company headquartered in the Northern District of California. The indictment covers charges including wire fraud conspiracy, transmission of damaging code to protected computers, computer fraud conspiracy, unauthorised access for financial gain, and aggravated identity theft.
The Excel attachments prompted recipients to enable a macro, which then fetched malware from the internet. Two tools were deployed: TVRAT, a remote access trojan also known as TVSPY or TeamSpy, and DarkVNC. Both handed the attackers remote control over infected machines and funnelled stolen data back to a command-and-control server based in the US. Around half the victims were American, with a notable concentration in the Northern District of California.
TVRAT works by bundling legitimate, digitally signed TeamViewer binaries with a malicious DLL file. The fake library loads itself ahead of the genuine Windows equivalent through DLL search order hijacking, then hooks nearly 50 Windows APIs to keep TeamViewer completely invisible to the victim. The infected machine quietly reports its TeamViewer ID to a C2 server, and that ID combined with a preset password is all the attacker needs to connect remotely. Because the main executable's signature checks out, nothing looks obviously wrong to the casual observer.
DarkVNC takes a different approach. It creates a hidden desktop on the compromised machine, letting the operator poke around without any visible sign of intrusion. The tool was first advertised on the Exploit forum in November 2016, so its appearance in this campaign shortly afterwards is hardly surprising.
The whole delivery mechanism depended on Office macro execution, something Microsoft finally killed by default in 2022 for files downloaded from the internet. A bit late, but better than never.
A shared document in the email account tied to the campaign also contained e-commerce login credentials and personal data belonging to hundreds of victims, which gives a fairly clear picture of what Aktulaev and his associates intended to do with the access they gained.
Aktulaev has denied any wrongdoing. Earlier this year, the Russian Embassy in Nicosia told state media outlets RIA Novosti and TASS that he had no knowledge of the US charges. The DoJ, for its part, was careful to note that charges are allegations and that Aktulaev is presumed innocent until proven guilty.
The case is a reminder that freelance and job-hunting platforms have become a well-worn attack surface. In February 2025, ESET reported North Korean hackers running similar freelance-platform lures against software developers. Last month, Check Point Research documented a Lazarus Group campaign pairing fake job offers with a remote-access backdoor, while CERT-UA flagged a Sandworm-linked cluster making contact through job-site chat before pushing a VPN client that could execute commands on the victim's machine.
Different actors, same basic playbook. A fake job listing or a plausible-looking message from a recruiter remains one of the more reliable ways to get someone to open a file they really shouldn't.