"Roughly 255 fake accounts" were used to send malware-laced Excel attachments to about 80,000 users, the U.S. Department of Justice says — an operation whose central figure has now been extradited and charged.
The charges and the accused
The U.S. Department of Justice has charged a Russian national, Searzhudin Tamirlanovich Aktulaev, 40, after his extradition from Cyprus on August 28. Aktulaev was arrested in Cyprus in May 2025 and made his initial appearance in federal court in San Francisco on August 31, where the indictment filed on June 1, 2021, was unsealed. He was remanded to federal custody.
The indictment alleges a conspiracy and a campaign spanning at least June 2016 through November 2017. It charges Aktulaev with:
- conspiracy to commit wire fraud;
- transmission of a program, information, code, or command to cause damage to protected computers;
- conspiracy to commit computer fraud;
- unauthorized access to a protected computer to obtain information for financial gain and to obtain value;
- aggravated identity theft.
The DoJ emphasized that the indictment contains allegations only and that Aktulaev is presumed innocent unless and until proven guilty. Aktulaev has denied guilt and, according to statements from the Russian Embassy in Nicosia reported by RIA Novosti and TASS earlier this year, said he was unaware of the U.S. charges.
Platform, scale, and victims
The indictment describes the service used to reach victims only as "a well-known freelance employment technology company" based in the Northern District of California. Prosecutors say approximately 255 fake accounts on that freelance platform were used to contact roughly 80,000 of its users with messages containing malicious Excel attachments.
Thousands of infected computers were reported to have called back to a command-and-control (C2) domain hosted in the United States. Approximately half of the victims were located in the United States, many within the Northern District of California. A shared document in the email account used in the scheme contained e-commerce login credentials and personally identifiable information (PII) for hundreds of victims, the DoJ said.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildThe malware: TVRAT (TeamSpy/TeamViewer module) and DarkVNC
The indictment names two malware types that were delivered by the campaign: a variant of TVRAT (also called TVSPY or TeamSpy) and DarkVNC. Both gave operators remote control of infected systems and sent stolen data back to the C2 server for collection and use in fraud or other criminal activity.
The DoJ noted that TVRAT exploits a TeamViewer vulnerability. Russian cybersecurity vendor Kaspersky used the same term in a March 2013 report on TeamSpy, saying the malicious module "uses a vulnerability in TeamViewer v6 known as Dll-hijacking." In February 2017, a TeamViewer spokesman told Security Affairs, "We have no evidence to assume a vulnerability of our software," per contemporaneous reporting cited in the DoJ release.
Independent analysis cited in the DoJ release describes how the TVRAT-style samples worked: an Excel macro fetched a password-protected installer that bundled legitimate, digitally signed TeamViewer binaries with a malicious msimg32.dll. That DLL is loaded in place of the genuine Windows DLL via DLL search order hijacking, and once loaded it hooks nearly 50 Windows APIs to suppress the TeamViewer window and dialogs. The infected machine then reports its TeamViewer ID to a C2 server; that ID, together with a preset password, was enough for operators to connect remotely, security researchers said.
DarkVNC, described by eSentire in a February 2024 analysis, is a hidden virtual network computing (hVNC) utility first advertised on the Exploit forum on November 24, 2016. DarkVNC creates a concealed desktop on the infected machine for an operator to control invisibly.
Delivery mechanism: Excel macros and a changed defensive landscape
The indictment alleges that the campaign relied on Excel attachments that prompted recipients to run a macro; the macro then downloaded malware from the internet. This delivery approach exploited users' willingness or promptness to enable macros in Office documents.
Notably, Microsoft has blocked Visual Basic for Applications (VBA) macros by default since 2022 in Office files obtained from the internet on Windows devices — a defensive change that directly affects the delivery step the campaign relied on. Despite that change, the DoJ's account shows how older delivery chains continued to produce widespread infections during the 2016–2017 window alleged in the indictment.
What this means for technologists, affected enterprises, and job seekers
Technologists and security teams: the case underscores the risk of remote-access malware that leverages legitimate-signed binaries and DLL-hijacking to evade signature checks — and of concealed-desktop tools such as hVNC. Defenders will watch for indicators related to TeamViewer IDs, msimg32.dll misuse, and C2 activity hosted in the United States as described in the indictment and related analyses.
Affected enterprises and procurement leaders: the indictment highlights that freelancing and recruitment platforms can be abused at scale. The presence of a shared document containing e-commerce credentials and hundreds of PII records in the scheme's email account underscores the need for monitoring and rapid response to credential exposure tied to vendor and platform communications.
End users and job seekers: the campaign used fake recruiter accounts and Excel attachments to deliver remote-access tools. As the DoJ notes and contemporaneous security reporting confirms, the initial step required running a macro contained in an Office attachment — a reminder that caution with unsolicited job-related attachments remains relevant even as platform defenses evolve.
The extradition and unsealing of a 2021 indictment fold a long-running, large-scale phishing and malware campaign back into public view. With Aktulaev in U.S. custody and charges pending, the case will test not only prosecutorial proof but also the degree to which long-past campaigns continue to inform current defensive practice.




