CYBERSECURITY

Extradited Russian Hacker Charged in Excel Malware Scheme Targeting Freelancers

Extradited Russian Hacker Charged in Excel Malware Scheme Targeting Freelancers

How the Fake Accounts Were Used to Spread Malware

Searzhudin Tamirlanovich Aktulaev, a 40-year-old Russian national, was extradited from Cyprus to the United States on August 28, 2026, and charged by the Department of Justice with orchestrating a malware campaign that used fake freelance accounts to distribute malicious Excel files to approximately 80,000 users in 2016 and 2017. The indictment alleges he created around 255 fraudulent profiles on a freelance platform to lure victims into opening infected attachments.

Prosecutors say Aktulaev used social engineering tactics, posing as potential clients offering work, to trick freelancers into downloading Excel files embedded with malware. Once opened, the files installed malicious software designed to steal sensitive data, including login credentials and financial information. The campaign specifically targeted users of the platform during a two-year span, exploiting trust in professional networking environments.

What Protections Were Lacking at the Time?

The DOJ’s filing details how Aktulaev registered numerous accounts using stolen or fabricated identities, then contacted freelancers with seemingly legitimate job offers. Each message included an Excel attachment that, when enabled, executed macros to install remote access tools. Investigators traced the infrastructure back to servers linked to the defendant, confirming his role in managing the distribution network. The malware allowed attackers to monitor keystrokes, capture screenshots, and exfiltrate data from compromised machines.

In 2016 and 2017, many freelance platforms had limited safeguards against account abuse and malicious file sharing. Macro-based attacks in Office documents were a common vector, and user awareness of such threats remained low. The case highlights how attackers exploited both technical vulnerabilities and human psychology, relying on the expectation of professional communication to bypass suspicion. Since then, platforms have improved file scanning and account verification, but similar tactics persist in modified forms.

What malware was used in the attack? The Excel files contained macros that installed remote access trojans, enabling attackers to control infected systems and steal data.

Frequently Asked Questions

How was Aktulaev identified? Digital forensics traced the fraudulent accounts and malware servers to his personal identifiers, including email addresses and payment methods linked to the fraudulent profiles.

Is the freelance platform named in the indictment? No, the Department of Justice did not disclose the name of the platform in the charging documents, citing ongoing investigative sensitivities.

Content written by Daniel Cross for tech-site.news editorial team, AI-assisted.

Comments

Leave a comment