Breaking News
Menu
Advertisement

U.S. Extradites Hacker Behind Massive Excel Macro Malware Campaign Targeting Freelancers

U.S. Extradites Hacker Behind Massive Excel Macro Malware Campaign Targeting Freelancers
100%

A massive Excel macro malware campaign that targeted 80,000 freelance workers has culminated in the U.S. extradition of a Russian national. The cyberattack leveraged malicious spreadsheet attachments to deploy remote access trojans, silently hijacking thousands of computers to steal e-commerce credentials and personal data.

This case serves as a critical warning for remote workers, freelancers, and organizations relying on external contractors. Understanding how these legacy macro-based attacks operate is essential for securing modern digital workspaces against evolving social engineering tactics.

The U.S. Department of Justice (DoJ) charged Searzhudin Tamirlanovich Aktulaev, 40, who was extradited from Cyprus on August 28 after his initial arrest in May 2025. He made his initial appearance in a San Francisco federal court on August 31. The indictment, originally filed on June 1, 2021, details how he used roughly 255 fake accounts on a prominent freelance platform to target users between June 2016 and November 2017.

The attack relied on malicious Excel attachments that prompted victims to execute a macro. Once triggered, the macro downloaded two primary payloads: TVRAT (also known as TVSPY or TeamSpy) and DarkVNC. Both tools exfiltrated personally identifiable information (PII) to a U.S.-hosted command-and-control (C2) server.

How the Excel Macro Malware Hijacked Systems

The technical execution of the malware was highly sophisticated. TVRAT utilized a technique known as DLL search order hijacking to load a malicious msimg32.dll file instead of the genuine Windows dynamic-link library. This allowed the malware to bypass standard signature checks on the main executable.

By hooking nearly 50 Windows Application Programming Interfaces (APIs), the malware successfully prevented the TeamViewer interface and dialog boxes from appearing on the victim's screen. The infected machine then reported its TeamViewer ID to the C2 server, granting attackers remote access using a preset password.

We have no evidence to assume a vulnerability of our software.

- TeamViewer

While Kaspersky previously noted the module used a vulnerability in TeamViewer v6, the company denied any inherent flaws. Meanwhile, DarkVNC operated as a hidden virtual network computing (hVNC) utility, creating a concealed desktop that granted attackers full remote control without alerting the user.

Actionable Steps: Defending Against Excel Macro Malware

Although Microsoft has blocked Visual Basic for Applications (VBA) macros by default since 2022 in Office files obtained from the internet, users must remain vigilant against evolving delivery methods.

  • Verify Macro Settings: Ensure your Excel Trust Center settings are configured to disable all macros with notification, preventing automatic execution.
  • Scrutinize Freelance Attachments: Never enable content or bypass Protected View for unsolicited spreadsheets from job platforms or unknown recruiters.
  • Monitor Background Processes: Regularly check Task Manager for unexpected remote access tools or hidden desktop sessions that consume unusual CPU resources.

The Freelance Economy's Blind Spot

The prosecution of Aktulaev highlights a glaring reality: the wheels of cyber justice move incredibly slowly. A campaign that compromised thousands of machines in 2016 and 2017 is only now seeing courtroom action in late 2026, underscoring why proactive defense is far more valuable than retroactive prosecution.

More importantly, this incident exposes the structural vulnerability of the gig economy. State-sponsored actors, including North Korea's Lazarus Group and the Sandworm-linked cluster, are actively mimicking these exact tactics on job-hunting sites today. As corporations harden their internal networks, freelance platforms have become the path of least resistance, requiring companies to extend zero-trust security models to their external contractors.

Did you like this article?
Advertisement

Popular Searches