Overview
The U.S. Department of Justice (DoJ) has charged Searzhudin Tamirlanovich Aktulaev, a 40‑year‑old Russian national extradited from Cyprus, for orchestrating a malware campaign that infected tens of thousands of computers through Excel attachments. The indictment alleges that Aktulaev used 255 fake freelance platform accounts between 2016 and 2017 to spread malware to roughly 80,000 users worldwide.
Attack Chain
- Phishing emails: Messages carried Excel attachments disguised as legitimate files.
- Macro execution: Victims were prompted to enable macros, which then downloaded malware.
- Malware types:
- TVRAT (TeamSpy): Exploited DLL hijacking in TeamViewer to provide remote access.
- DarkVNC: Created hidden desktops for attackers to control infected machines.
- Data theft: Stolen credentials and PII were funneled to U.S.‑hosted command‑and‑control servers.
Technical Insights
- DLL hijacking: Malicious
msimg32.dllreplaced legitimate Windows DLLs, bypassing signature checks. - API hooking: Nearly 50 Windows APIs were hooked to conceal TeamViewer activity.
- Hidden VNC: Allowed attackers to operate on concealed desktops without user awareness.
- Credential exposure: Hundreds of e‑commerce logins and personal records were compromised.
Legal Charges
Aktulaev faces multiple charges, including:
- Wire fraud conspiracy
- Computer fraud
- Unauthorized access for financial gain
- Aggravated identity theft
He has denied guilt, and the indictment notes he is presumed innocent until proven otherwise.
Broader Context
- Freelance platforms targeted: Job‑hunting and freelancing sites remain recurring lures for cybercriminals.
- North Korean campaigns: ESET reported similar tactics in 2025 targeting developers.
- Fake recruiter attacks: Recent campaigns by Lazarus and Sandworm used fake job offers and VPN clients to deliver backdoors.
Expert in the Cloud Insight
This case underscores how social engineering and trusted platforms can be weaponized to deliver malware at scale. By exploiting Excel macros and DLL hijacking, attackers bypassed traditional defenses and gained persistent remote access. The lesson is clear: organizations must enforce strict macro policies, monitor DLL loads, and treat freelance/job platforms as high‑risk vectors for phishing campaigns.
Leave a Reply