Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Russian Hacker Extradited for Major Excel Malware Attack

Russian Hacker Extradited for Major Excel Malware Attack

Posted on September 2, 2026 By CWS

The U.S. Department of Justice has indicted a Russian citizen, extradited from Cyprus, over a sophisticated Excel malware campaign. The suspect, Searzhudin Tamirlanovich Aktulaev, allegedly used approximately 255 fraudulent accounts on a freelance website to distribute contaminated Excel files to around 80,000 users between 2016 and 2017. This case highlights significant cybersecurity threats in the digital freelancing space.

Details of the Cybercrime Campaign

Aktulaev, aged 40, was apprehended in Cyprus in May 2025 and appeared in a San Francisco federal court on August 31. The indictment, revealed on the same day, accuses him of exploiting a “well-known freelance employment technology company” based in Northern California. The malware attack reportedly involved two types of malware, TVRAT and DarkVNC, both facilitating unauthorized access and control over infected computers.

TVRAT, a variant of the TeamViewer remote access trojan, allowed the hackers to take control of computers remotely. The malware allegedly communicated with a command-and-control server located in the U.S., affecting thousands of systems, with a significant number of victims residing in California.

Technical Aspects of the Malware

The malicious Excel files contained macros that, once enabled, downloaded the malware onto victims’ computers. TVRAT, as per the DoJ’s statement, exploited a known vulnerability in TeamViewer software, although TeamViewer has denied any inherent flaws in their system. The compromised systems transmitted stolen data back to the attackers, facilitating further criminal activities.

DarkVNC, another tool used in the campaign, creates a hidden desktop on the compromised machine, granting the attackers control without detection. This utility was first advertised on cybercriminal forums in late 2016, indicating its role in various illicit operations.

Legal Proceedings and Implications

Aktulaev faces multiple charges, including conspiracy to commit wire fraud, unauthorized computer access, and aggravated identity theft. Despite these charges, he maintains his innocence, as stated by the Russian Embassy in Cyprus. The indictment currently consists of allegations, with defendants presumed innocent until proven guilty in a court of law.

This case underscores the persistent risks that freelancing and job-seeking platforms face from cybercriminals. Recent reports indicate that these platforms continue to be targets for state-sponsored hackers, further emphasizing the need for enhanced cybersecurity measures.

As the investigation proceeds, the cybersecurity community remains vigilant, emphasizing the importance of protecting online platforms from such sophisticated threats.

The Hacker News Tags:Cybercrime, Cybersecurity, DarkVNC, DoJ, Excel malware, Extradition, freelance platform, identity theft, Russian hacker, TVRAT

Post navigation

Previous Post: SonicWall Vulnerabilities Under Active Exploit Alert
Next Post: Sality P2P Botnet Dismantled After Decades

Related Posts

64% of 3rd-Party Applications Access Sensitive Data Without Justification 64% of 3rd-Party Applications Access Sensitive Data Without Justification The Hacker News
Linux PamDOORa Backdoor Exploits PAM to Steal SSH Credentials Linux PamDOORa Backdoor Exploits PAM to Steal SSH Credentials The Hacker News
Critical n8n Vulnerabilities Risk Remote Code Execution Critical n8n Vulnerabilities Risk Remote Code Execution The Hacker News
Agentic AI’s Role in Defense Hinges on Secure Infrastructure Agentic AI’s Role in Defense Hinges on Secure Infrastructure The Hacker News
New Linux Zapscape Vulnerability Threatens KVM Hosts New Linux Zapscape Vulnerability Threatens KVM Hosts The Hacker News
New ClayRat Spyware Targets Android Users via Fake WhatsApp and TikTok Apps New ClayRat Spyware Targets Android Users via Fake WhatsApp and TikTok Apps The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • HPE Fabric Composer Vulnerabilities Expose Critical Security Risks
  • Sality P2P Botnet Dismantled After Decades
  • Russian Hacker Extradited for Major Excel Malware Attack
  • SonicWall Vulnerabilities Under Active Exploit Alert
  • Chrome and Firefox Updates Fix Critical Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • HPE Fabric Composer Vulnerabilities Expose Critical Security Risks
  • Sality P2P Botnet Dismantled After Decades
  • Russian Hacker Extradited for Major Excel Malware Attack
  • SonicWall Vulnerabilities Under Active Exploit Alert
  • Chrome and Firefox Updates Fix Critical Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark