Russian National Extradited to US Over Excel Macro Malware Campaign That Hit ~80,000 Freelance Platform Users With TVRAT and DarkVNC
Searzhudin Tamirlanovich Aktulaev, 40, was extradited from Cyprus to the US on August 28, 2026 and charged over a June 2016–November 2017 campaign that used ~255 fake accounts on a freelance employment platform to send macro-enabled Excel attachments to about…
The US Department of Justice has charged Searzhudin Tamirlanovich Aktulaev, 40, a Russian national arrested in Cyprus in May 2025 and extradited to the US on August 28, 2026, over an Excel macro malware campaign run between June 2016 and November 2017 (described by The Hacker News as 2016–2017). According to the indictment — originally filed June 1, 2021 and unsealed August 31, 2026 — Aktulaev and co-conspirators used roughly 255 fake accounts on a freelance employment platform's messaging system to send macro-laden Excel attachments to about 80,000 users, deploying TVRAT (also known as TeamSpy/TVSPY) and DarkVNC remote access trojans for remote access and data theft. Thousands of infected machines called back to a US-hosted C2 domain that was paid for with virtual currency; Infosecurity Magazine reports roughly half of the 80,000 affected users were in the US. Stolen credentials and PII were stored in the shared email account used in the scheme (The Hacker News) and used for fraud (Infosecurity Magazine). The two outlets list the charges slightly differently: The Hacker News cites wire fraud conspiracy and aggravated identity theft, while Infosecurity Magazine adds computer damage and unauthorized access; the maximum penalty reported is up to 20 years for conspiracy to commit wire fraud, plus additional terms and fines. The defendant denies guilt.
- Suspect: Searzhudin Tamirlanovich Aktulaev, 40, Russian national; arrested in Cyprus in May 2025; extradited to the US on August 28, 2026.
- Indictment originally filed June 1, 2021 and unsealed August 31, 2026 (per The Hacker News); the defendant denies guilt.
- Campaign timeframe: June 2016 to November 2017 (Infosecurity Magazine); The Hacker News describes it as 2016–2017.
- Delivery: ~255 fake accounts on a freelance employment platform's messaging system were used to send macro-enabled Excel attachments to ~80,000 users.
- Malware: TVRAT (TeamSpy/TVSPY) and DarkVNC remote access trojans used for remote access and data theft; DarkVNC is an hVNC tool that creates a concealed desktop on victims' machines.
- TVRAT technique: The Hacker News says it used TeamViewer DLL search order hijacking (msimg32.dll) to hide connections; Infosecurity Magazine characterizes it as exploiting a TeamViewer vulnerability.
- C2: Thousands of infected machines called back to a US-hosted C2 domain; C2 infrastructure was paid for with virtual currency; roughly half of the ~80,000 affected users were in the US (Infosecurity Magazine).
- Stolen credentials and PII were stored in the shared email account used in the scheme (The Hacker News); stolen data was used for fraud (Infosecurity Magazine).
Coverage timelineoldest first · each row is one article
- · 13d agoExtradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands
The Hacker News· 25
US DoJ charged extradited Russian Searzhudin Aktulaev for a 2016-2017 Excel macro campaign infecting ~80,000 freelance platform users with TVRAT and DarkVNC.