-
Federal authorities extradited 40-year-old Russian national Searzhudin Tamirlanovich Aktulaev from Cyprus to face serious computer fraud and identity theft charges in San Francisco.
-
The suspect reportedly introduced 255 counterfeit accounts on a much-utilized freelancing website to deliver malware-infested Excel files to around 80,000 potential victims.
-
The operation used VBA macros to infect the computers of victims with TVRAT and DarkVNC malware, employing DLL search order hijacking.
Federal prosecutors in California have recently unsealed criminal charges against a suspected Russian cybercriminal extradited from Cyprus. The individual allegedly ran a massive email scam, and he subsequently infected tens of thousands of business computers worldwide.
The defendant utilized a large number of fake accounts on the biggest job placement website to send malware files. As a result, the malicious documents equipped the hacker with the tool for spying and acquiring confidential information from its victims.
Extradition and Initial Court Appearance in San Francisco
Authorities brought forty-year-old Russian citizen Searzhudin Tamirlanovich Aktulaev into federal custody after completing his extradition process on August 28. Officials originally arrested the suspect in Cyprus during May 2025 following a long-standing U.S. law enforcement request.
Aktulaev later appeared in a San Francisco courtroom, where a federal judge ordered him remanded into custody. The court unsealed an indictment originally filed in June, five years ago that names the defendant in several serious conspiracy counts.
The underlying indictment focuses on an extensive cyberattack wave conducted from June 2016 through November the following year. Prosecutors allege that Aktulaev created roughly 255 fake user profiles on a major freelance job site.
By employing these fabricated profiles, the criminal was able to transmit harmful Microsoft Excel files to almost 80,000 users of the platform. In addition, the scheme threatened systems all over the world; around 50 percent of the known victims were located within the United States.
The fake user profiles made it easier for the perpetrators to contact victims without setting off security alerts. By presenting their message as inquiries in relation to real job projects, the criminals lured unsuspecting victims into downloading files.
Consequently, the scam spread rapidly across the professional network, affecting numerous remote workers and business entities.
Exploit Mechanics and Dual Malware Payloads
When targeted users opened the malicious spreadsheet files, hidden prompts asked them to enable embedded macro code. Once activated, the macro scripts immediately downloaded secondary malware payloads from external servers.
The campaign deployed two main tools to compromise endpoint security: a modified remote access trojan named TVRAT and a hidden virtual network computing tool known as DarkVNC. Consequently, both malicious utilities granted the attackers full remote control over affected desktop environments.
The TVRAT variant relies on a clever execution method called DLL search order hijacking. The macro dropped a legitimate, digitally signed TeamViewer installer alongside a malicious file named msimg32.dll.
Because the main application executable was officially signed, standard security checks showed no suspicious activity. However, the fake dynamic-link library intercepted dozens of system operations to hide all remote window controls from the victim.
Alternatively, the DarkVNC payload created a completely hidden secondary desktop on the compromised host machine. This concealed interface allowed the attackers to navigate local files and execute commands without alerting the active user.
Fortunately, tech giant Microsoft blocked internet-sourced VBA macros by default in Office, effectively shutting down this primary infection vector. Modern security tools now inspect incoming Office documents more aggressively to prevent similar macro execution attempts.
Data Theft, Command and Control, and Legal Charges
The malicious software regularly transmitted harvested victim data back to a central command and control server infrastructure. Analysts inspecting the infrastructure discovered a centralized database containing compromised e-commerce credentials alongside extensive personally identifiable information.
Additionally, thousands of infected client machines reported back to server domains hosted inside the United States. The orchestrators made use of the misappropriated personal data to engage in hacking attempts and unauthorized access to accounts.
Among the misappropriated details were important login credentials, payment information, and private files of various clients. The hackers ensured comprehensive system access and stole confidential saved cookies and passwords without the knowledge of users. The workers operated continuously in the background, exfiltrating fresh logs whenever an infected computer connected to the internet.
The federal indictment against Aktulaev includes a number of serious charges like conspiracy to commit wire fraud and the crime of computer fraud. There are also charges concerning the transmission of malware, illegal gain of access, and aggravated identity theft.
The person may face a punishment of twenty years in jail on the main wire fraud accusation if proved guilty. Meanwhile, Russian diplomatic representatives stated that Aktulaev previously denied all wrongdoing before his extradition.
The U.S. government is also targeting Russian cybercriminals through the State Department’s Rewards for Justice program, which offers up to $10 million for information on groups UNC5792 and UNC4221. The groups targeted officials, military leaders, journalists, and allies through phishing attacks on Signal and WhatsApp, stealing Signal Backup Recovery Keys to access past chats.
Persistent Targeting of Online Job Platforms
This case demonstrates an ongoing trend of how cyber crooks are misusing employment sites to carry out criminal schemes. Criminal crews create fake job offers or freelance tasks that entice unsuspecting applicants to open dangerous files.
For instance, experts in cybersecurity reported their findings on the use of fraudulent recruitment messages by state-sponsored hackers who targeted software developers with the help of backdoor programs. Similarly, other advanced hacking units contacted job seekers through site chat functions to push trojanized software utilities.
Organized threat groups favor recruitment channels because job applicants naturally expect to receive external files, such as project briefs and resumes. Hence, individuals must be very careful while opening files received through freelance websites and professional networks.
Companies should use updated endpoint security tools, establish strict procedures for effective administration of macro setups, and educate the personnel about social engineering schemes. Verifying the file extension as well as checking unsolicited attachments is obligatory for preventing remote access Trojans.
Site administrators must also implement stricter identity verification protocols for employer accounts registered on recruitment platforms. Also, verifying client profiles prior to allowing bulk messaging can prevent many instances of the dissemination of malicious attachments.
Tackling social engineering campaigns of multi-stage vectors requires active cooperation between the job portals, cybersecurity companies, and international law enforcement agencies.