Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands
AI Summary
A Russian national, Searzhudin Tamirlanovich Aktulaev, has been extradited and charged by the U.S. Department of Justice for orchestrating a malware campaign between 2016 and 2017 that targeted users of a major freelance platform. The campaign involved sending malicious Excel attachments that prompted victims to enable macros, which then downloaded either TVRAT (a TeamViewer-based RAT) or DarkVNC malware. These malware variants provided remote access to infected systems and exfiltrated stolen data, including e-commerce credentials and PII, to a U.S.-hosted command-and-control server. The attack exploited DLL search order hijacking to load a malicious msimg32.dll, allowing stealthy persistence and remote control.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Filename | msimg32.dll | Details → |