VYPR
breachPublished Sep 2, 2026· 1 source

Russian National Charged in US for Orchestrating 2016-2017 Excel Malware Campaign

A Russian national extradited from Cyprus faces U.S. charges for allegedly leading a malware campaign that used fake freelance accounts to distribute malicious Excel attachments to thousands of users.

The U.S. Department of Justice (DoJ) has brought charges against Searzhudin Tamirlanovich Aktulaev, a Russian national extradited from Cyprus, for his alleged role in orchestrating a malware campaign between 2016 and 2017. Aktulaev, 40, is accused of using approximately 255 fake accounts on a prominent freelance platform to distribute malicious Excel attachments to around 80,000 users. He was arrested in Cyprus in May 2025 and made his initial appearance in federal court in San Francisco on August 31, where he was remanded to federal custody.

The indictment, unsealed on the day of his court appearance, details how the campaign operated. Messages sent from these fake accounts contained Excel attachments designed to prompt recipients into running a macro. Once executed, this macro would download malware from the internet. The indictment specifies two types of malware used: a variant of TVRAT (also known as TVSPY or TeamSpy), a TeamViewer remote access trojan, and DarkVNC, a hidden virtual network computing (hVNC) utility. Both malware types provided operators with remote control over the infected computers.

Thousands of computers infected with TVRAT were observed communicating with command-and-control (C2) domains hosted within the U.S., with roughly half of the victims located in the United States. The investigation also uncovered a shared document within an email account used in the scheme, which contained e-commerce login credentials and personally identifiable information (PII) belonging to hundreds of victims. This data was likely collected and exploited by Aktulaev and his alleged co-conspirators for fraudulent purposes.

Aktulaev faces multiple charges, including conspiracy to commit wire fraud, transmission of damaging code to protected computers, conspiracy to commit computer fraud, unauthorized access to protected computers for financial gain, and aggravated identity theft. The DoJ alleges that from June 2016 to November 2017, the malware downloaded via the Excel macros enabled operators to gain remote access and steal data, which was then sent to the C2 server for criminal activities.

Technical analysis of the malware reveals sophisticated techniques. TVRAT is noted to exploit a vulnerability in TeamViewer, specifically a DLL-hijacking method that allows a malicious DLL to be loaded in place of a legitimate one, bypassing signature checks. Avast reported in April 2017 that this technique involved a password-protected installer bundling legitimate TeamViewer binaries with a malicious msimg32.dll. DarkVNC, identified by eSentire in February 2024, creates a concealed desktop on the infected machine for operators to control.

While Microsoft has since implemented default blocking of VBA macros from internet-sourced Office files on Windows devices, a measure that would hinder this specific delivery method, the campaign highlights the persistent threat of social engineering. Aktulaev has reportedly denied guilt and claimed ignorance of the U.S. charges, according to statements from the Russian Embassy in Nicosia. The DoJ emphasizes that the indictment contains allegations, and Aktulaev is presumed innocent until proven guilty.

The case also underscores a recurring tactic where threat actors leverage job-hunting and freelancing platforms to lure victims. This trend has been observed in other recent campaigns, including those attributed to North Korean hackers and the Lazarus Group, who have also used fake job offers and freelance lures to distribute malware and steal credentials.

Synthesized by Vypr AI