GBHackers

255 Fake Accounts Used to Send Malicious Excel Files to 80,000 Freelancers


A Russian national has been extradited to the United States to face charges over an alleged phishing operation that used 255 fake accounts on a freelance employment platform to distribute malicious Microsoft Excel files to roughly 80,000 users.

Federal prosecutors allege that Searzhudin Tamirlanovich Aktulaev, 40, orchestrated the campaign between June 2016 and November 2017, using the platform’s internal messaging capability to reach freelancers at scale.

The indictment, originally filed in June 2021 and unsealed after Aktulaev’s recent court appearance, describes an operation built around weaponized Excel attachments, social engineering, remote-access malware, credential theft, and command-and-control infrastructure.

Once a recipient executed the embedded macro, it downloaded malware from the internet onto the victim system.

The alleged campaign demonstrates how legitimate online marketplaces can be abused as trusted initial-access channels.

Freelancers commonly exchange project files, invoices, requirements documents, portfolios, and spreadsheets with prospective clients, making Excel attachments a particularly effective lure.

Rather than relying on conventional email phishing, the operators allegedly used an established employment platform’s messaging infrastructure to give the files greater credibility.

At the time of the activity, VBA macro-enabled documents remained a widely exploited malware-delivery mechanism. Microsoft has since introduced stronger default protections for macros in Office files downloaded from the internet.

However, threat actors continue to adapt by using alternative attachment formats, cloud-hosted payloads, HTML smuggling, password-protected archives, and social-engineering prompts to bypass security controls.

The indictment identifies two malware families allegedly deployed through the malicious spreadsheets: TVRAT and DarkVNC.

TVRAT, also known as TVSPY or TeamSpy, is described by prosecutors as a TeamViewer Remote Access Trojan that exploited a vulnerability associated with the remote administration software to provide remote control of infected systems.

The second payload, DarkVNC, allegedly offered comparable remote-access capabilities through VNC Viewer. Both tools enabled operators to access compromised devices and exfiltrate victim data to command-and-control servers.

This pairing is technically notable because it combines credential theft with interactive remote administration.

Once a device is compromised, an attacker can potentially collect browser data, authentication material, saved passwords, payment information, local files, and business communications.

According to the U.S. Department of Justice, messages sent from approximately 255 fraudulent accounts carried Microsoft Excel attachments designed to persuade recipients to enable macros.

Remote-control access can also be used to conduct follow-on fraud directly from a victim’s system, reducing the likelihood that activity appears anomalous to banks, e-commerce platforms, or other online services.

Excel Malware Campaign

Investigators said both malware strains transmitted stolen data to C2 infrastructure, where the information was allegedly collected for fraud and other criminal activity.

Prosecutors further alleged that the domains used for command-and-control communications were paid for with virtual currency.

Thousands of TVRAT-infected devices reportedly connected back to a command-and-control domain hosted in the United States.

A database recovered from that infrastructure allegedly contained records tied to thousands of victims.

Approximately half of the affected users were located in the United States, including many in the Northern District of California, according to the indictment.

Authorities also found a shared document in an email account allegedly used in the operation containing e-commerce credentials and personally identifiable information for hundreds of victims.

The scale of the campaign highlights the identity-security exposure facing independent workers.

Freelancers often operate outside centralized enterprise security controls, frequently use personal endpoints, and may manage multiple client accounts, cloud services, payment platforms, and business identities from a single machine.

A compromise can therefore expose both the individual and their clients.

Aktulaev was arrested in Cyprus in May 2025 and extradited to the United States on August 28, 2026, according to the Justice Department.

He made his initial appearance in federal court in San Francisco and was remanded to federal custody. A status conference is scheduled for October 5, 2026, before U.S. District Judge Donato.

He faces charges including conspiracy to commit wire fraud, computer-damage offenses, conspiracy to commit computer fraud, unauthorized access to protected computers, and aggravated identity theft.

If convicted, he could face substantial prison terms and financial penalties, including a potential 20-year maximum sentence for the wire-fraud conspiracy count.

The FBI investigated the case, which is being prosecuted by the National Security, Cyber, and Special Prosecutions Section.

As with all criminal indictments, the allegations remain unproven, and Aktulaev is presumed innocent unless and until proven guilty in court.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.



Source link