- What: Russian national charged for malware scheme
- Impact: 80,000 users targeted via fake Excel attachments
Malware Russian national charged in US for malware scheme targeting 80,000 users September 3, 2026 Share By SC Staff (Adobe Stock) A Russian national has been charged by the U.S. Department of Justice for allegedly operating approximately 255 fake accounts on a freelance platform to distribute malware-laced Excel attachments to around 80,000 users in 2016 and 2017. Searzhudin Tamirlanovich Aktulaev, 40, was extradited from Cyprus to face charges including conspiracy to commit wire fraud and aggravated identity theft. The indictment details a sophisticated scheme that leveraged a popular freelance employment platform to distribute malicious software, with thousands of computers ultimately infected, as reported by The Hacker News. Aktulaev is accused of sending emails with Excel attachments that, when opened, prompted recipients to run a macro. This macro then downloaded one of two malware types: a variant of TVRAT (also known as TeamSpy) or DarkVNC. Both malware types provided operators with remote control of infected computers and exfiltrated stolen data to command-and-control servers. The indictment, filed in June 2021, alleges that a shared document within the scheme's email account contained e-commerce login credentials and personally identifiable information for hundreds of victims. Approximately half of the infected computers were located in the U.S. Microsoft has since implemented measures to block VBA macros from untrusted internet sources by default. Source: The Hacker News SC Staff Related Malware New browser malware uses remote commands to control Windows systems SC Staff September 3, 2026 The malware, disguised as a "privacy browser," was distributed via a deceptive sponsored search result after an employee mistyped a URL. Malware Malicious Composer themes deliver spyware to unpatched iOS devices SC Staff September 2, 2026 The malicious code performs two main functions: a mobile ad-fraud and gambling-redirect chain, and a WebKit-to-kernel exploit chain on iPhones that installs spyware. Malware New PackClient RAT sold on Telegram SC Staff September 2, 2026 The PackClient RAT, observed by Proofpoint, offers a wide range of capabilities including file theft, remote shell execution, screen capture, and keylogging. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Adware You can skip this ad in 5 seconds