The U.S. Department of Justice has charged a Russian national with deploying approximately 255 fraudulent accounts on a freelance platform to distribute malware-infected Excel attachments to roughly 80,000 users during 2016 and 2017. Searzhudin Tamirlanovich Aktulaev, 40, was extradited from Cyprus on August 28 and appeared in federal court in San Francisco on August 31, where he was placed in federal custody. The indictment, originally filed on June 1, 2021, and unsealed the day of his court appearance, accuses Aktulaev of conspiracy to commit wire fraud, transmission of harmful code to protected computers, conspiracy to commit computer fraud, unauthorized access to obtain information for financial gain, and aggravated identity theft.

According to the indictment, the scheme ran from at least June 2016 through November 2017, with messages containing Excel files that instructed recipients to enable a macro. That macro then retrieved malware from the internet in two forms: a version of TVRAT, a TeamViewer remote access trojan also called TVSPY or TeamSpy, and DarkVNC. Both malware types granted operators remote control of infected machines and transmitted stolen data to a command-and-control server, from which Aktulaev and his co-conspirators collected it for fraud or other criminal activity. Thousands of computers infected with TVRAT contacted a C2 domain hosted in the United States, with about half of the victims located within the country, many in the Northern District of California. A shared document in the email account associated with the operation held e-commerce login credentials and personally identifiable information for hundreds of victims. The indictment identifies the targeted platform only as "a well-known freelance employment technology company" based in the Northern District of California.

The Justice Department's statement notes that TVRAT exploits a vulnerability in TeamViewer, a claim that mirrors Russian cybersecurity firm Kaspersky's March 2013 analysis of TeamSpy, which stated the malicious module "uses a vulnerability in TeamViewer v6 known as Dll-hijacking." However, a TeamViewer spokesman told Security Affairs in February 2017 that "We have no evidence to assume a vulnerability of our software." Avast's April 2017 analysis of a TeamSpy sample spread through Excel macros found the macro downloaded a password-protected installer bundling legitimate, digitally signed TeamViewer binaries with a malicious msimg32.dll file. That library gets loaded instead of the genuine Windows DLL through DLL search order hijacking, and once active, it blocks nearly 50 Windows APIs to hide the TeamViewer window and dialogs from the victim. DarkVNC, according to eSentire's February 2024 analysis, is a hidden virtual network computing utility first advertised on the Exploit forum on November 24, 2016, that creates a concealed desktop on infected machines for operator control.

Aktulaev was arrested in Cyprus in May 2025 and has denied guilt, saying he was unaware of the U.S. charges, according to statements from the Russian Embassy in Nicosia reported by RIA Novosti and TASS earlier this year. The DoJ noted that the indictment contains allegations only and that Aktulaev is presumed innocent unless and until proven guilty. The case highlights the continuing use of job-hunting and freelancing sites as lures by state-sponsored actors, with ESET reporting in February 2025 that North Korean hackers were using the same freelance-platform tactic against software developers. Last month, fake-recruiter campaigns were documented by Check Point Research, which observed a Lazarus Group operation pairing fake job offers with a remote-access backdoor, and by Ukraine's CERT-UA, which said a Sandworm-linked cluster contacted candidates through job-site chat before delivering a VPN client capable of running commands. Microsoft has blocked Visual Basic for Applications macros by default since 2022 in Office files obtained from the internet on Windows devices, the delivery method this campaign relied on, though the 2016-2017 timeframe predates that protection. As freelance platforms expand their user bases, the attack surface for credential theft and malware distribution through trusted professional networks will likely grow, forcing both platforms and users to balance accessibility with verification rigor. The persistence of campaigns targeting job seekers suggests adversaries view employment marketplaces as durable entry points where social engineering blends seamlessly with professional routine.