• 4 minuti
  • Pubblicato

Freelance Platform Breach: Russian Hacker Extradited for Excel Malware Attack

Matteo Sala Giornalista e analista tecnologico QWERTYmag

Scritto da Matteo Sala

Freelance Platform Breach: Russian Hacker Extradited for Excel Malware Attack QWERTYmag © www.qwertymag.it
Freelance Platform Breach: Russian Hacker Extradited for Excel Malware Attack © www.qwertymag.it

A Russian national extradited from Cyprus now faces U.S. federal charges after allegedly orchestrating a massive malware campaign via Excel attachments, compromising tens of thousands of freelance platform users and exposing sensitive data.

Federal prosecutors have unmasked the architect behind a sprawling malware campaign that weaponized a freelance platform, infecting thousands of computers and siphoning sensitive data from unsuspecting users. Searzhudin Tamirlanovich Aktulaev, 40, extradited from Cyprus, now sits in a San Francisco jail, accused of orchestrating one of the most audacious cyberattacks to ever target the gig economy.

Aktulaev's alleged operation was anything but subtle. According to the U.S. Department of Justice, he and his co-conspirators created 255 fake accounts on a major freelance employment platform, bombarding roughly 80,000 users with Excel files rigged to deploy remote access trojans. The indictment, unsealed as Aktulaev appeared in court, details a campaign that ran from mid-2016 through late 2017, exploiting the trust and digital routines of freelancers across the United States-half of the victims were American, many in California's tech heartland.

Come funzionava l'attacco: Excel come cavallo di Troia

The attack's mechanics were as simple as they were effective. Victims received messages containing Excel attachments that, once opened and enabled for macros, silently downloaded malware from the internet. Two strains dominated: a variant of TVRAT-also known as TeamSpy or TVSPY-and DarkVNC, a hidden virtual network computing tool. Both gave attackers full remote control, allowing them to harvest login credentials, e-commerce access, and personally identifiable information from hundreds of victims. The infected machines dutifully reported back to a U.S.-hosted command-and-control server, feeding a steady stream of stolen data to the operators.

Security researchers have dissected the technical sleight of hand. Avast's analysis revealed that the malicious Excel macro fetched a password-protected installer bundling legitimate TeamViewer binaries with a rogue DLL, exploiting Windows' DLL search order to evade detection. Once in place, the malware suppressed TeamViewer's interface, leaving victims oblivious as their systems were commandeered. Meanwhile, DarkVNC created a concealed desktop, granting attackers invisible access to the compromised device.

Le accuse e la risposta delle aziende coinvolte

Aktulaev faces a battery of charges: conspiracy to commit wire fraud, computer fraud, unauthorized access for financial gain, and aggravated identity theft. The Department of Justice alleges that the stolen data was used for further fraud and criminal activity, with the freelance platform's reputation and user trust collateral damage in the process. Notably, the indictment refers to the platform only as "a well-known freelance employment technology company," but the scale and method leave little doubt about the platform's prominence.

TeamViewer, whose software was leveraged in the attack, has consistently denied any vulnerability in its product, despite Kaspersky and other researchers highlighting DLL-hijacking as the vector. Microsoft, for its part, has since blocked VBA macros by default in Office files downloaded from the internet-a move that would have neutralized this campaign's delivery method had it been in place at the time.

Implicazioni per la sicurezza delle piattaforme di lavoro digitale

This case lands as digital job platforms remain a favorite hunting ground for cybercriminals and state-backed actors alike. In recent months, ESET and Check Point Research have documented North Korean and Sandworm-linked groups using similar freelance and job-recruitment lures to compromise developers and IT professionals. The pattern is clear: wherever digital trust and opportunity intersect, attackers are quick to exploit the weakest link-often, the human at the keyboard.

Aktulaev, through statements relayed by the Russian Embassy in Nicosia, has denied any wrongdoing and claims ignorance of the U.S. charges. The Department of Justice, however, is pressing forward, emphasizing that the indictment remains an allegation and that Aktulaev is presumed innocent until proven guilty.

What emerges from this case is a stark lesson for the digital workforce: even the most familiar platforms can become vectors for sophisticated attacks when basic security hygiene is neglected. The U.S. response-extradition, prosecution, and technical countermeasures-signals a new level of seriousness in defending the gig economy's digital infrastructure. But as attackers adapt and platforms remain lucrative targets, only a relentless focus on user education, technical safeguards, and rapid incident response will keep the next wave of cybercriminals at bay. The days of trusting an Excel attachment from a stranger are, for anyone paying attention, definitively over.

Articoli correlati