hacker-news · Crawled Sep 2, 2026

Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands

1 IoCs 2 Malware
Read original article ↗

AI Summary

A Russian national, Searzhudin Tamirlanovich Aktulaev, has been extradited and charged by the U.S. Department of Justice for orchestrating a malware campaign between 2016 and 2017 that targeted users of a major freelance platform. The campaign involved sending malicious Excel attachments that prompted victims to enable macros, which then downloaded either TVRAT (a TeamViewer-based RAT) or DarkVNC malware. These malware variants provided remote access to infected systems and exfiltrated stolen data, including e-commerce credentials and PII, to a U.S.-hosted command-and-control server. The attack exploited DLL search order hijacking to load a malicious msimg32.dll, allowing stealthy persistence and remote control.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 1 extracted

Type Value Detail
Filename msimg32.dll Details →

MITRE ATT&CK TTPs 4 techniques