Russian Hacker Charged Over Excel Malware Campaign

← Back to articles

Russian Hacker Charged Over Excel Malware Campaign

A Russian national who was extradited from Cyprus on August 28 has been charged by the U.S. Department of Justice for running a malware campaign that sent malicious Excel files to roughly 80,000 users of a freelance marketplace in 2016 and 2017. The indictment says the suspect, Searzhudin Tamirlanovich Aktulaev, 40, created about 255 fake accounts on the platform to distribute the infected attachments.

The victims were freelancers and businesses that relied on the marketplace to find work or hire talent. Each fake account posted job offers or messages that included an Excel attachment. The file contained a macro‑based payload that, when enabled, installed a remote access tool on the victim’s computer. This gave the attacker control over the system, allowing data theft and further spread of the malware.

The scheme relied on social engineering. Users often trust files received from a platform they consider reputable, so they were more likely to open the Excel document and enable macros, a common step required for many legitimate spreadsheets. Once the macro ran, it silently connected to a command‑and‑control server operated by the hacker.

To protect yourself from similar attacks, avoid opening Excel files from unknown senders and never enable macros unless you are certain the document is safe. Use reputable antivirus software and keep it up to date. Regularly back up important files to an offline location. If you receive a suspicious attachment, scan it with a free online virus scanner like the tools available at ComputerScams.com before opening.

If you think you may have been targeted, change passwords for any accounts that could have been compromised and enable two‑factor authentication where possible. Monitor your financial statements and credit reports for unusual activity, as attackers often seek to harvest personal data for identity theft.

The Department of Justice’s filing provides a rare glimpse into how cybercriminals exploit trusted platforms to spread malware at scale. While the case is still pending, it underscores the need for vigilance when handling email attachments, even from seemingly legitimate sources.

Stay cautious, verify the source of any file, and keep your security software current to reduce the risk of infection.

Source: Read the original report

Scroll to Top