Malware Campaign

Overview

The U.S. Department of Justice (DoJ) has charged Searzhudin Tamirlanovich Aktulaev, a 40‑year‑old Russian national extradited from Cyprus, for orchestrating a malware campaign that infected tens of thousands of computers through Excel attachments. The indictment alleges that Aktulaev used 255 fake freelance platform accounts between 2016 and 2017 to spread malware to roughly 80,000 users worldwide.

Attack Chain

  • Phishing emails: Messages carried Excel attachments disguised as legitimate files.
  • Macro execution: Victims were prompted to enable macros, which then downloaded malware.
  • Malware types:
    • TVRAT (TeamSpy): Exploited DLL hijacking in TeamViewer to provide remote access.
    • DarkVNC: Created hidden desktops for attackers to control infected machines.
  • Data theft: Stolen credentials and PII were funneled to U.S.‑hosted command‑and‑control servers.

Technical Insights

  • DLL hijacking: Malicious msimg32.dll replaced legitimate Windows DLLs, bypassing signature checks.
  • API hooking: Nearly 50 Windows APIs were hooked to conceal TeamViewer activity.
  • Hidden VNC: Allowed attackers to operate on concealed desktops without user awareness.
  • Credential exposure: Hundreds of e‑commerce logins and personal records were compromised.

Legal Charges

Aktulaev faces multiple charges, including:

  • Wire fraud conspiracy
  • Computer fraud
  • Unauthorized access for financial gain
  • Aggravated identity theft

He has denied guilt, and the indictment notes he is presumed innocent until proven otherwise.

Broader Context

  • Freelance platforms targeted: Job‑hunting and freelancing sites remain recurring lures for cybercriminals.
  • North Korean campaigns: ESET reported similar tactics in 2025 targeting developers.
  • Fake recruiter attacks: Recent campaigns by Lazarus and Sandworm used fake job offers and VPN clients to deliver backdoors.

Expert in the Cloud Insight

This case underscores how social engineering and trusted platforms can be weaponized to deliver malware at scale. By exploiting Excel macros and DLL hijacking, attackers bypassed traditional defenses and gained persistent remote access. The lesson is clear: organizations must enforce strict macro policies, monitor DLL loads, and treat freelance/job platforms as high‑risk vectors for phishing campaigns.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.