Russian Hacker Indicted for TVRAT and DarkVNC Excel Malware Attacks
Key Takeaways A Russian national has been indicted for a malware campaign that targeted approximately 80,000 freelance workers globally. The operation leveraged fraudulent accounts on a freelance...
Key Takeaways
- A Russian national has been indicted for a malware campaign that targeted approximately 80,000 freelance workers globally.
- The operation leveraged fraudulent accounts on a freelance platform and malicious Excel documents to deploy TVRAT and DarkVNC malware.
- Attackers used social engineering to trick victims into enabling macros, leading to remote control and data theft.
- The case highlights the persistent threat of weaponized office documents, particularly for independent contractors.
A Russian national is facing charges in the United States in connection with an extensive malware operation that allegedly compromised about 80,000 freelance professionals worldwide. This sophisticated campaign reportedly exploited a popular online employment platform, utilizing deceptive Excel documents to infiltrate systems and steal sensitive data.
Table Of Content
Prosecutors assert that the scheme involved creating numerous fake accounts and distributing booby-trapped Excel files. These files, disguised as legitimate project-related communications, served as a conduit for malware delivery, enabling attackers to seize control of victim computers and exfiltrate information.
The incident underscores the enduring effectiveness of using common office file formats for malicious purposes, especially when targeting independent workers who frequently exchange project files with unknown contacts. The alleged operation spanned from June 2016 to November 2017, during which messages were sent from approximately 255 fraudulent accounts on a freelance employment platform.
According to The U.S. Attorney’s Office, Northern District of California, said in a report, each malicious Excel attachment prompted recipients to enable macros. This seemingly innocuous action allegedly initiated the download of malware from the internet, demonstrating how a simple user interaction can bridge the gap between a convincing social engineering attempt and a severe system compromise.
The campaign reportedly deployed TVRAT and DarkVNC, remote access trojans (RATs) that granted attackers the ability to remotely view and control infected devices. The compromised data was subsequently transmitted to command-and-control (C2) servers and, as alleged by prosecutors, later exploited for various fraudulent and criminal activities.
Russian Hacker Indicted for Using Excel Malware
Searzhudin Tamirlanovich Aktulaev, 40, a Russian national, has been indicted by a federal grand jury on multiple charges, including conspiracy, damage to protected computers, and aggravated identity theft. Authorities confirmed his arrest in Cyprus in May 2025 and subsequent extradition to the United States. Aktulaev made his initial court appearance in San Francisco on August 31.
The indictment details that TVRAT, also known as TVSPY or TeamSpy, exploited a vulnerability within TeamViewer to achieve remote control over compromised systems. While this case focuses on the earlier TVRAT campaign, it serves as a reminder of the broader risks associated with remote-control software and how attackers frequently abuse such tools.
Similarly, DarkVNC provided remote control functionalities, often through VNC Viewer. This situation highlights a crucial security lesson: all unexpected requests to open files or grant access, particularly those involving remote support software, demand rigorous scrutiny. Furthermore, organizations must remain vigilant about patching new TeamViewer code flaws, which can introduce additional security exposures.
Victims, Stolen Data, and Defence
Prosecutors revealed that thousands of infected computers communicated with a U.S.-hosted command-and-control domain, with its registration paid using virtual currency. Approximately half of the alleged victims were located in the United States, including a significant number in Northern California. A database recovered from this infrastructure reportedly contained a list of thousands of victims, illustrating the wide reach of the malicious campaign.
Investigators also discovered a shared document within an email account allegedly used in the operation. This document contained e-commerce login credentials and personal information belonging to hundreds of victims. The continued efficacy of such lures stems from their ability to mimic routine work files, a tactic frequently observed in weaponized spreadsheet attacks.
The investigation was a collaborative effort involving the Federal Bureau of Investigation, with the Justice Department’s Office of International Affairs facilitating Aktulaev’s extradition on August 28, 2026. The prosecution is being handled by the National Security, Cyber, and Special Prosecutions Section. The charging documents do not disclose the name of the freelance platform or specific malicious domains, file hashes, or attachment filenames.
Aktulaev remains in federal custody, with a status conference scheduled for October 5, 2026. It is important to note that the charges are allegations, and he is presumed innocent until proven guilty. If convicted, he faces potential penalties including prison sentences and fines for the charged offenses.
What You Should Do
- Exercise extreme caution with unsolicited spreadsheets and other attachments, even if they appear work-related.
- Never enable macros in documents unless you are absolutely certain of their origin and legitimacy.
- Verify unexpected file requests through a separate, trusted communication channel (e.g., a phone call to the sender).
- Configure your systems to limit or block macros from internet-sourced files.
- Keep all remote-access software, such as TeamViewer and VNC Viewer, fully updated to the latest secure versions.
- Monitor network traffic for unusual outbound connections that could indicate malware activity.
- Implement robust email filtering and security awareness training to combat phishing attacks that deliver malware disguised as legitimate documents.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.