Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Dropbox Confirms 5,000 Accounts Compromised via Lenovo ID Flaw
September 2, 2026
TukTuk Locker Ransomware Targets Credentials, Disables Security
September 2, 2026
Russian Hacker Indicted for TVRAT and DarkVNC Excel Malware Attacks
September 2, 2026
Home/Threats/Russian Hacker Indicted for TVRAT and DarkVNC Excel Malware Attacks
Threats

Russian Hacker Indicted for TVRAT and DarkVNC Excel Malware Attacks

Key Takeaways A Russian national has been indicted for a malware campaign that targeted approximately 80,000 freelance workers globally. The operation leveraged fraudulent accounts on a freelance...

Jennifer sherman
Jennifer sherman
September 2, 2026 4 Min Read
3 0

Key Takeaways

  • A Russian national has been indicted for a malware campaign that targeted approximately 80,000 freelance workers globally.
  • The operation leveraged fraudulent accounts on a freelance platform and malicious Excel documents to deploy TVRAT and DarkVNC malware.
  • Attackers used social engineering to trick victims into enabling macros, leading to remote control and data theft.
  • The case highlights the persistent threat of weaponized office documents, particularly for independent contractors.

A Russian national is facing charges in the United States in connection with an extensive malware operation that allegedly compromised about 80,000 freelance professionals worldwide. This sophisticated campaign reportedly exploited a popular online employment platform, utilizing deceptive Excel documents to infiltrate systems and steal sensitive data.

Table Of Content

  • Key Takeaways
  • Russian Hacker Indicted for Using Excel Malware
  • Victims, Stolen Data, and Defence
  • What You Should Do

Prosecutors assert that the scheme involved creating numerous fake accounts and distributing booby-trapped Excel files. These files, disguised as legitimate project-related communications, served as a conduit for malware delivery, enabling attackers to seize control of victim computers and exfiltrate information.

The incident underscores the enduring effectiveness of using common office file formats for malicious purposes, especially when targeting independent workers who frequently exchange project files with unknown contacts. The alleged operation spanned from June 2016 to November 2017, during which messages were sent from approximately 255 fraudulent accounts on a freelance employment platform.

According to The U.S. Attorney’s Office, Northern District of California, said in a report, each malicious Excel attachment prompted recipients to enable macros. This seemingly innocuous action allegedly initiated the download of malware from the internet, demonstrating how a simple user interaction can bridge the gap between a convincing social engineering attempt and a severe system compromise.

The campaign reportedly deployed TVRAT and DarkVNC, remote access trojans (RATs) that granted attackers the ability to remotely view and control infected devices. The compromised data was subsequently transmitted to command-and-control (C2) servers and, as alleged by prosecutors, later exploited for various fraudulent and criminal activities.

Russian Hacker Indicted for Using Excel Malware

Searzhudin Tamirlanovich Aktulaev, 40, a Russian national, has been indicted by a federal grand jury on multiple charges, including conspiracy, damage to protected computers, and aggravated identity theft. Authorities confirmed his arrest in Cyprus in May 2025 and subsequent extradition to the United States. Aktulaev made his initial court appearance in San Francisco on August 31.

The indictment details that TVRAT, also known as TVSPY or TeamSpy, exploited a vulnerability within TeamViewer to achieve remote control over compromised systems. While this case focuses on the earlier TVRAT campaign, it serves as a reminder of the broader risks associated with remote-control software and how attackers frequently abuse such tools.

Similarly, DarkVNC provided remote control functionalities, often through VNC Viewer. This situation highlights a crucial security lesson: all unexpected requests to open files or grant access, particularly those involving remote support software, demand rigorous scrutiny. Furthermore, organizations must remain vigilant about patching new TeamViewer code flaws, which can introduce additional security exposures.

Victims, Stolen Data, and Defence

Prosecutors revealed that thousands of infected computers communicated with a U.S.-hosted command-and-control domain, with its registration paid using virtual currency. Approximately half of the alleged victims were located in the United States, including a significant number in Northern California. A database recovered from this infrastructure reportedly contained a list of thousands of victims, illustrating the wide reach of the malicious campaign.

Investigators also discovered a shared document within an email account allegedly used in the operation. This document contained e-commerce login credentials and personal information belonging to hundreds of victims. The continued efficacy of such lures stems from their ability to mimic routine work files, a tactic frequently observed in weaponized spreadsheet attacks.

The investigation was a collaborative effort involving the Federal Bureau of Investigation, with the Justice Department’s Office of International Affairs facilitating Aktulaev’s extradition on August 28, 2026. The prosecution is being handled by the National Security, Cyber, and Special Prosecutions Section. The charging documents do not disclose the name of the freelance platform or specific malicious domains, file hashes, or attachment filenames.

Aktulaev remains in federal custody, with a status conference scheduled for October 5, 2026. It is important to note that the charges are allegations, and he is presumed innocent until proven guilty. If convicted, he faces potential penalties including prison sentences and fines for the charged offenses.

What You Should Do

  • Exercise extreme caution with unsolicited spreadsheets and other attachments, even if they appear work-related.
  • Never enable macros in documents unless you are absolutely certain of their origin and legitimacy.
  • Verify unexpected file requests through a separate, trusted communication channel (e.g., a phone call to the sender).
  • Configure your systems to limit or block macros from internet-sourced files.
  • Keep all remote-access software, such as TeamViewer and VNC Viewer, fully updated to the latest secure versions.
  • Monitor network traffic for unusual outbound connections that could indicate malware activity.
  • Implement robust email filtering and security awareness training to combat phishing attacks that deliver malware disguised as legitimate documents.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwarePatchphishingSecurity

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

FBI and CrowdStrike Disrupt Sality Botnet

Next Post

TukTuk Locker Ransomware Targets Credentials, Disables Security

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
BREEZE COMET Hackers Use AI Malware to Target Brazil Banks
September 2, 2026
Claude AI Creates Pre-Auth RCE Exploit for WAGO PLCs
September 2, 2026
Palo Alto Networks Acquires Console for AI-Driven Autonomous Security Operations
September 2, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us