HomeCyber Balkans255 Fake Accounts Used to Distribute Malicious Excel Files to 80,000 Freelancers

255 Fake Accounts Used to Distribute Malicious Excel Files to 80,000 Freelancers

Published on

spot_img

Russian National Extradited to the U.S. for Alleged Phishing Operation Targeting Freelancers

In a significant development in the realm of cybercrime, a Russian national, Searzhudin Tamirlanovich Aktulaev, has been extradited to the United States to stand trial for his purported involvement in an extensive phishing operation. This operation allegedly utilized a staggering 255 fake accounts on a popular freelance employment platform to distribute malicious Microsoft Excel files, potentially impacting around 80,000 users.

Federal prosecutors contend that the 40-year-old Aktulaev masterminded this nefarious campaign between June 2016 and November 2017. Notably, he is accused of leveraging the internal messaging capabilities of the freelance platform to efficiently reach a wide array of freelancers. This tactic enabled him to exploit the trust that users typically have in the platform’s communication infrastructure.

The indictment against Aktulaev was initially filed in June 2021 and remained sealed until his recent court appearance. The document outlines a complex operation that relied on various cybercriminal tactics, including the use of "weaponized" Excel attachments, social engineering techniques, remote-access malware, and credential theft. These elements coalesced to create a command-and-control infrastructure designed to manipulate unsuspecting victims.

The modus operandi involved enticing recipients to execute embedded macros within the Excel files. Upon doing so, malware was downloaded from the internet onto the victim’s system. This phishing campaign highlights a troubling trend in which legitimate online marketplaces can be misused as effective conduits for cybercrime, providing perpetrators with seemingly credible avenues for attack.

Freelancers often share critical project files, invoices, and other sensitive documents in their communications. This practice makes the use of Excel attachments a highly effective lure for cybercriminals, as these documents are trusted and frequently opened. Instead of relying on conventional phishing tactics via email, the alleged operators of this scheme exploited the established messaging framework of the employment platform, allowing their malicious files to gain additional credibility.

During the time of these offenses, VBA macro-enabled documents were a widely acknowledged method for malware delivery. Microsoft has since bolstered its security protocols by implementing stricter default protections for macros in Office files downloaded from the web. Yet, cybercriminals like Aktulaev continue to adapt, employing alternative methods such as cloud-hosted payloads and social engineering techniques to evade security measures.

The indictment further identifies two specific malware families that were allegedly deployed through the malicious Excel spreadsheets: TVRAT and DarkVNC. Prosecutors describe TVRAT, or TeamSpy, as a remote access Trojan that exploits vulnerabilities in remote administration software, enabling remote control of infected systems. On the other hand, DarkVNC purportedly offered similar remote access capabilities. The combination of these two tools would facilitate both credential theft and interactive remote administration, creating a dangerous synergy for attackers.

Once a device is compromised, the implications can be severe. Attackers may potentially harvest a wealth of sensitive data, including browser history, authentication credentials, saved passwords, and financial information. Additionally, authorities note that messages dispatched from the fraudulent accounts featured Microsoft Excel attachments designed specifically to persuade recipients to enable macros, thereby facilitating the malware download.

The ramifications extend beyond individual victims. With remote-control access, attackers could conduct further fraudulent activities directly from a compromised system, making it significantly less likely that such actions would raise alarms with banks or online service providers.

Investigators have indicated that both malware strains involved in this operation transmitted stolen data back to a command-and-control (C2) infrastructure, which was allegedly financed using virtual currency. Reports suggest that thousands of devices infected with TVRAT connected back to a C2 domain hosted within the United States. A database recovered from this infrastructure purportedly contained extensive records linked to thousands of victims, half of whom were located in the United States, particularly in the Northern District of California.

Authorities discovered a shared document in an email account thought to be used in the operation, containing e-commerce credentials and personally identifiable information for hundreds of victims. This scale of cyber exploitation underscores a troubling vulnerability in the identity security landscape for freelancers, who often work without the safeguarding of centralized enterprise security controls. They are known to operate personal endpoints, manage multiple client accounts, and access cloud services from a single machine, which can escalate the damage resulting from a compromise.

Aktulaev was apprehended in Cyprus in May 2025 and subsequently extradited to the United States on August 28, 2026. Following his initial court appearance in San Francisco, he was ordered to remain in federal custody. A status conference is slated for October 5, 2026, presided over by U.S. District Judge Donato.

Facing a litany of serious charges, including conspiracy to commit wire fraud and aggravated identity theft, Aktulaev is potentially at risk of facing lengthy prison sentences and significant financial penalties. The maximum sentence for the wire-fraud conspiracy count could extend as high as 20 years. The investigation is being led by the FBI and is prosecuted by the National Security, Cyber, and Special Prosecutions Section.

It is essential to note that, as with all criminal indictments, the allegations against Aktulaev remain unproven. He is presumed innocent until proven guilty in a court of law. The ongoing case highlights the persistent threat posed by cybercriminals and the urgent need for individuals, particularly freelancers, to adopt robust security practices to safeguard their sensitive information.

Source link

Latest articles

Anthropic Unveils Zero-Retention AI Safety Monitoring for Enterprises

Anthropic Unveils Enterprise Frontier Safeguards to Tackle AI Misuse While Protecting Data Privacy In a...

Security Debt Exposes Companies to AI-Driven Attacks

CEO Nikesh Arora Warns of Potential Breaches Due to Cybersecurity Debt In a recent address...

Nutex Health Reports Data Breach as Hackers Threaten to Leak Patient Information

Nutex Health Faces Data Breach: Patients' Sensitive Information Compromised Nutex Health, a prominent US healthcare...

How China Built the Infrastructure for State-Sponsored Hacking

The Quartermaster Model of Hacking: A Deep Dive into QTFY Operations Over the past year,...

More like this

Anthropic Unveils Zero-Retention AI Safety Monitoring for Enterprises

Anthropic Unveils Enterprise Frontier Safeguards to Tackle AI Misuse While Protecting Data Privacy In a...

Security Debt Exposes Companies to AI-Driven Attacks

CEO Nikesh Arora Warns of Potential Breaches Due to Cybersecurity Debt In a recent address...

Nutex Health Reports Data Breach as Hackers Threaten to Leak Patient Information

Nutex Health Faces Data Breach: Patients' Sensitive Information Compromised Nutex Health, a prominent US healthcare...