A Russian individual has been charged in the United States for allegedly orchestrating a malware campaign that targeted approximately 80,000 freelancers globally. This operation reportedly involved the use of deceptive accounts and compromised Excel files to extract data and gain unauthorized access to computers.
Malware Campaign Targeting Freelancers
The indictment highlights how seemingly innocuous office files can become tools for cybercriminals to exploit independent workers. Between June 2016 and November 2017, fraudulent messages were disseminated through roughly 255 fake accounts on a popular freelance job platform. These messages contained Excel attachments prompting recipients to enable macros, which then downloaded harmful software from the internet.
The U.S. Attorney’s Office for the Northern District of California reported that the operation utilized TVRAT and DarkVNC, software tools that allowed attackers to remotely view and control compromised systems. Stolen data was allegedly sent to command-and-control servers for use in fraudulent activities.
Details of the Indictment
Searzhudin Tamirlanovich Aktulaev, aged 40, has been charged with conspiracy, damaging protected computers, and aggravated identity theft. He was apprehended in Cyprus in May 2025, extradited to the U.S., and appeared in a San Francisco court on August 31.
According to court documents, TVRAT, also known as TVSPY or TeamSpy, exploited vulnerabilities in remote-control software like TeamViewer. DarkVNC provided similar capabilities via VNC Viewer. These incidents underscore the importance of scrutinizing unexpected requests to open files or allow access, especially given the ongoing risks associated with such software.
Impact and Defensive Measures
Investigators disclosed that numerous infected devices communicated with a U.S.-based command-and-control server, funded through virtual currency. It is estimated that about half of the victims were located in the U.S., notably in Northern California. A database linked to the operation contained personal information and e-commerce credentials of thousands of individuals.
To protect against such threats, freelancers and organizations are advised to approach unsolicited spreadsheets with caution, avoid enabling macros without verification, utilize secure channels for file validation, and maintain updated remote-access software. These practices are critical in defending against phishing and malware disguised as legitimate documents.
The investigation was conducted by the FBI, with assistance from the Justice Department’s Office of International Affairs in securing Aktulaev’s extradition. The prosecution is managed by the National Security, Cyber, and Special Prosecutions Section. Specific details about the freelance platform or malicious domains remain undisclosed.
Aktulaev is currently detained and awaits a status conference on October 5, 2026. All charges are allegations, and he is presumed innocent until proven guilty. If convicted, he could face substantial prison time and fines for the alleged crimes.
