Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Unveiling the Complex Web of a Russian Hacker's Excel Malware Campaign: A Masterclass in Malicious Deception




A Russian national, Searzhudin Tamirlanovich Aktulaev, has been charged with using a sophisticated Excel malware campaign to compromise the security of thousands of computers. The campaign, which spanned several years, utilized fake accounts, malicious Excel attachments, and two strains of malware to steal sensitive information and commit financial fraud. Aktulaev, 40, was arrested in Cyprus in May 2025 and extradited to the United States on August 28, where he faces charges related to conspiracy, wire fraud, and identity theft.

  • Swati Khandelwal breaks down a sophisticated Excel malware campaign launched by Russian national Searzhudin Tamirlanovich Aktulaev.
  • The campaign used fake accounts, malicious Excel attachments, and two strains of malware (TVRAT and DarkVNC) to compromise thousands of computers.
  • The malware was designed to grant remote access to infected computers, allowing attackers to pilfer sensitive information and use it for financial gain.
  • The TVRAT malware exploits a vulnerability in TeamViewer remote access software and uses DLL search order hijacking to prevent detection.
  • The DarkVNC malware creates a concealed desktop for attackers to control, used to steal sensitive information and commit financial fraud.
  • US Department of Justice charges Aktulaev with conspiracy to commit wire fraud and other crimes.
  • Aktulaev was arrested in Cyprus and extradited to the US, where he faces charges and awaits trial.
  • The case highlights the ongoing threat posed by state-sponsored actors using job-hunting and freelancing sites as a lure for malicious activities.



  • Swati Khandelwal, a renowned cybersecurity expert, breaks down the intricacies of a sophisticated Excel malware campaign launched by a Russian national, Searzhudin Tamirlanovich Aktulaev, against thousands of unsuspecting victims. The campaign, which spanned several years, utilized a combination of fake accounts on a freelance platform, malicious Excel attachments, and two strains of malware, TVRAT and DarkVNC, to compromise the security of its targets.

    The campaign, which began in 2016, involved the use of roughly 255 fake accounts on a freelance platform, with the primary goal of sending malware-laced Excel attachments to approximately 80,000 users. The malicious attachments, which were designed to be opened by recipients, contained a macro that, when executed, downloaded the malware from the internet. The malware, in turn, granted remote access to the infected computer, allowing the attackers to pilfer sensitive information and use it for financial gain.

    The TVRAT malware, also known as TeamViewer remote access trojan (RAT) or TVSPY, exploits a vulnerability in TeamViewer, a widely used remote access software. The malware also utilized a technique called DLL search order hijacking, which allows the malicious library to hook nearly 50 Windows Application Programming Interfaces (APIs) to prevent the TeamViewer window and its dialogs from being displayed to the victim. This clever technique made it difficult for users to detect the malware, as the TeamViewer window remained visible, albeit without functionality.

    The DarkVNC malware, on the other hand, is a hidden virtual network computing (hVNC) utility that creates a concealed desktop on the infected machine for the operator to control. The malware was first advertised on the Exploit forum on November 24, 2016, and has since been used by attackers to steal sensitive information and commit financial fraud.

    The U.S. Department of Justice (DoJ) has charged Aktulaev with conspiracy to commit wire fraud, transmission of a program, information, code, or command to cause damage to protected computers, conspiracy to commit computer fraud, unauthorized access to a protected computer to obtain information for financial gain, and aggravated identity theft. The indictment, filed on June 1, 2021, alleges that Aktulaev used the malicious Excel attachments to compromise the security of thousands of computers, with approximately half of the victims located in the United States, many of them in the Northern District of California.

    Aktulaev, 40, was arrested in Cyprus in May 2025 and extradited to the United States on August 28. He made his initial appearance in federal court in San Francisco on August 31 and was remanded to federal custody. The DoJ noted that the indictment contains allegations only and that Aktulaev is presumed innocent unless and until proven guilty.

    The case highlights the ongoing threat posed by state-sponsored actors, who continue to use job-hunting and freelancing sites as a lure for their malicious activities. The development comes as the threat landscape continues to evolve, with new vulnerabilities and exploits being discovered on a daily basis.

    In conclusion, the case of Searzhudin Tamirlanovich Aktulaev serves as a stark reminder of the complexities and dangers of malicious Excel malware campaigns. The use of fake accounts, malicious attachments, and two strains of malware to compromise the security of thousands of computers is a testament to the cunning and sophistication of modern cyber threats. As the threat landscape continues to evolve, it is essential for users to remain vigilant and take steps to protect themselves against such malicious activities.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Unveiling-the-Complex-Web-of-a-Russian-Hackers-Excel-Malware-Campaign-A-Masterclass-in-Malicious-Deception-ehn.shtml

  • https://thehackernews.com/2026/09/extradited-russian-hacker-faces-charges.html


  • Published: Wed Sep 2 05:42:47 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us