A Russian national who was extradited from Cyprus on August 28, 2026, has been formally charged by the U.S. Department of Justice for orchestrating a large-scale malware campaign that used infected Excel attachments to infiltrate around 80,000 users on a major freelancing site. The case hinges on a scheme using fake accounts to distribute malicious macros that installed remote access tools, triggering federal wire fraud, computer fraud, and identity theft charges.
What Happened: Infection via Excel & Remote Access Tools
The accused, 40-year-old Searzhudin Tamirlanovich Aktulaev, allegedly set up roughly 255 fake profiles on a well-known freelance platform located in Northern California. Between June 2016 and November 2017, those profiles sent thousands of emails with Excel attachments that appeared legitimate but contained macros. Once run, these macros downloaded one of two remote access trojans: a variant of TVRAT (also known as TeamSpy or TVSPY) or DarkVNC.
Both malware types allowed threat actors to gain full remote control of infected PCs, exfiltrate personal data and login credentials, and carry out additional fraud. Many of the infections targeted U.S. users; the malware communicated with a command-and-control server hosted stateside.
The Legal Case: Charges & Extradition Details
Aktulaev was arrested in Cyprus in May 2025 and extradited to the U.S. in late August 2026. He made his first U.S. court appearance in San Francisco on August 31 and has since been held in federal custody. The indictment against him, unsealed upon his appearance, accuses him of conspiracy to commit wire fraud, conspiracy to commit computer fraud, unauthorized access of protected computers for financial gain, and aggravated identity theft.
A key allegation is that a shared document, accessed through email accounts tied to the scheme, contained e-commerce logins and personally identifiable information (PII) for hundreds of victims, further amplifying the severity of the offense. Aktulaev, however, has denied knowledge of the charges via statements reported by the Russian Embassy in Nicosia. The DoJ emphasizes that indictment claims are unproven unless a conviction results.
Tools & Tricks: How TVRAT & DarkVNC Operated
TVRAT, designed to exploit vulnerabilities in TeamViewer via DLL hijacking, installed through macros that loaded a malicious copy of a Windows system library (msimg32.dll). This technique hid malicious code inside otherwise signed binaries, allowing operators to avoid detection. DarkVNC worked differently—it created hidden desktops for attackers to control machines remotely without tipping off users.
Notably, macros in Office files downloaded from the internet have been blocked by default in Windows since 2022. Yet, many users still enabled macros manually—either knowingly or unknowingly—which allowed the campaign to succeed.
Why This Matters
This case underscores the ongoing risks posed by seemingly innocuous freelancing platforms, which are regularly exploited as fronts for cybercrime. In recent years, job-offer scams using remote-access tools have surged. The Aktulaev indictment joins similar trends involving state-linked threat groups employing fake job offers to deliver malware.
With Aktulaev now in U.S. custody and facing multiple charges, the outcome may set precedent in how extradited cybercriminals are prosecuted under international cooperation frameworks. It serves as a warning: using fake accounts and macro-laden files to distribute remote access malware is no longer low risk. For organizations and freelancers alike, vigilance around macros, third-party credentials, and platform security policies remains essential—and future cases will likely punish those who misuse remote access tools with ever greater severity.