Russian National Charged in US for Orchestrating 2016-2017 Excel Malware Campaign
A Russian national extradited from Cyprus faces U.S. charges for allegedly leading a malware campaign that used fake freelance accounts to distribute malicious Excel attachments to thousands of users.

The U.S. Department of Justice (DoJ) has brought charges against Searzhudin Tamirlanovich Aktulaev, a Russian national extradited from Cyprus, for his alleged role in orchestrating a malware campaign between 2016 and 2017. Aktulaev, 40, is accused of using approximately 255 fake accounts on a prominent freelance platform to distribute malicious Excel attachments to around 80,000 users. He was arrested in Cyprus in May 2025 and made his initial appearance in federal court in San Francisco on August 31, where he was remanded to federal custody.
The indictment, unsealed on the day of his court appearance, details how the campaign operated. Messages sent from these fake accounts contained Excel attachments designed to prompt recipients into running a macro. Once executed, this macro would download malware from the internet. The indictment specifies two types of malware used: a variant of TVRAT (also known as TVSPY or TeamSpy), a TeamViewer remote access trojan, and DarkVNC, a hidden virtual network computing (hVNC) utility. Both malware types provided operators with remote control over the infected computers.
Thousands of computers infected with TVRAT were observed communicating with command-and-control (C2) domains hosted within the U.S., with roughly half of the victims located in the United States. The investigation also uncovered a shared document within an email account used in the scheme, which contained e-commerce login credentials and personally identifiable information (PII) belonging to hundreds of victims. This data was likely collected and exploited by Aktulaev and his alleged co-conspirators for fraudulent purposes.
Aktulaev faces multiple charges, including conspiracy to commit wire fraud, transmission of damaging code to protected computers, conspiracy to commit computer fraud, unauthorized access to protected computers for financial gain, and aggravated identity theft. The DoJ alleges that from June 2016 to November 2017, the malware downloaded via the Excel macros enabled operators to gain remote access and steal data, which was then sent to the C2 server for criminal activities.
Technical analysis of the malware reveals sophisticated techniques. TVRAT is noted to exploit a vulnerability in TeamViewer, specifically a DLL-hijacking method that allows a malicious DLL to be loaded in place of a legitimate one, bypassing signature checks. Avast reported in April 2017 that this technique involved a password-protected installer bundling legitimate TeamViewer binaries with a malicious msimg32.dll. DarkVNC, identified by eSentire in February 2024, creates a concealed desktop on the infected machine for operators to control.
While Microsoft has since implemented default blocking of VBA macros from internet-sourced Office files on Windows devices, a measure that would hinder this specific delivery method, the campaign highlights the persistent threat of social engineering. Aktulaev has reportedly denied guilt and claimed ignorance of the U.S. charges, according to statements from the Russian Embassy in Nicosia. The DoJ emphasizes that the indictment contains allegations, and Aktulaev is presumed innocent until proven guilty.
The case also underscores a recurring tactic where threat actors leverage job-hunting and freelancing platforms to lure victims. This trend has been observed in other recent campaigns, including those attributed to North Korean hackers and the Lazarus Group, who have also used fake job offers and freelance lures to distribute malware and steal credentials.
The indictment details the specific malware families used in the campaign, TVRAT (also known as TVSPY or TeamSpy) and DarkVNC, which provided operators with remote control capabilities. Prosecutors allege that TVRAT exploited weaknesses associated with TeamViewer, while DarkVNC offered similar functionality via VNC Viewer. The investigation also recovered a document containing e-commerce login credentials and personal information belonging to hundreds of victims, underscoring the direct financial and identity theft impact of the operation.
The new article reports on the extradition of a Russian national to the United States to face charges related to a malware campaign. This campaign specifically targeted approximately 80,000 freelance users, aiming to steal their personal and financial data. The extradition underscores international cooperation in pursuing cybercriminals responsible for large-scale attacks.
The indictment against Searzhudin Tamirlanovich Aktulaev, unsealed this week, details the use of two specific malware strains: TVRAT (also known as TVSPY or TeamSpy), which exploits TeamViewer vulnerabilities, and DarkVNC, which targets VNC Viewer flaws. These tools allowed Aktulaev to gain remote access, steal data, and commit fraud. Prosecutors also revealed that Aktulaev used 255 fake user accounts on a freelance employment platform to distribute malicious Microsoft Excel attachments, leading to the infection of approximately 80,000 users between June 2016 and November 2017.
The indictment details that the malware campaign, active between June 2016 and November 2017, utilized approximately 255 fake accounts on a freelance platform to distribute malicious Microsoft Excel attachments. These attachments, when opened, prompted users to run macros that downloaded TVRAT (also known as TVSPY or TeamSpy) and DarkVNC malware, which granted attackers remote control and exfiltrated data. The malware infrastructure was hosted in the US, with half of the estimated 80,000 victims located in the same Northern California district as the freelance platform.