VMTech
Discuss a project

US Charges Russian National in Excel Malware Campaign

US Charges Russian National in Excel Malware Campaign

US charges follow Cyprus extradition

The US Department of Justice has charged Russian national Searzhudin Tamirlanovich Aktulaev, 40, over an alleged malware campaign that used roughly 255 fake accounts on a freelance platform to send weaponised Excel attachments to about 80,000 users between 2016 and 2017.

Aktulaev was arrested in Cyprus in May 2025 and extradited to the United States on August 28. He made his initial appearance in federal court in San Francisco on August 31 and was remanded to federal custody. The indictment was filed on June 1, 2021, and unsealed on the day of his appearance.

The charging document describes the targeted service only as a well-known freelance employment technology company based in the Northern District of California. Aktulaev faces counts including conspiracy to commit wire fraud, computer fraud, unauthorised access to protected computers for financial gain, transmission of code causing damage, and aggravated identity theft.

Excel macros delivered remote-access malware

Prosecutors allege that recipients received Excel files prompting them to run a macro. The macro downloaded malware from the internet, either a TVRAT variant or DarkVNC. Both tools gave operators remote control of the infected computer and transmitted stolen data to a command-and-control domain hosted in the United States.

Thousands of compromised computers were contacting that domain. Approximately half of the affected victims were in the United States, including many in the Northern District of California. A shared document in an email account used in the alleged operation contained e-commerce credentials and personally identifiable information for hundreds of victims.

TVRAT, also called TVSPY or TeamSpy, is described as a TeamViewer remote-access trojan. Kaspersky reported in 2013 that a malicious TeamSpy module used DLL hijacking associated with TeamViewer v6. Avast's 2017 analysis of a sample delivered through Excel macros found a password-protected installer combining signed TeamViewer binaries with a malicious msimg32.dll library.

Avast said the library was loaded through DLL search order hijacking and hooked nearly 50 Windows APIs to hide TeamViewer windows and dialogs. The compromised machine then reported its TeamViewer ID to a command-and-control server; that ID and a preset password could allow remote connection. DarkVNC is a hidden VNC utility that creates a concealed desktop for the operator.

Controls must address the delivery route

Microsoft has blocked VBA macros by default since 2022 for internet-originated Office files on Windows, addressing the delivery mechanism alleged in this case. Job and freelance platforms nevertheless remain recurring lures: ESET reported North Korean activity targeting software developers through a freelance-platform pretext in February 2025, while Check Point Research and CERT-UA documented recent fake-recruiter operations.

Aktulaev has denied guilt and said he was unaware of the US charges. The Department of Justice stressed that the indictment contains allegations and that he is presumed innocent unless proven guilty. For businesses, the practical implication is to preserve macro-blocking controls, scrutinise files sent through recruitment channels, and investigate unexpected remote-access software and outbound command-and-control connections.

#cybersecurity#malware#phishing#remotesecurity
Open analytics
On the site 0 views
min read 4 02.09.2026
Instagram

US Charges Russian National in Excel Malware Campaign

Open the post on Instagram ↗