A Russian national has been charged by the U.S. Department of Justice for allegedly operating approximately 255 fake accounts on a freelance platform to distribute malware-laced Excel attachments to around 80,000 users in 2016 and 2017. Searzhudin Tamirlanovich Aktulaev, 40, was extradited from Cyprus to face charges including conspiracy to commit wire fraud and aggravated identity theft. The indictment details a sophisticated scheme that leveraged a popular freelance employment platform to distribute malicious software, with thousands of computers ultimately infected, as reported by The Hacker News.Aktulaev is accused of sending emails with Excel attachments that, when opened, prompted recipients to run a macro. This macro then downloaded one of two malware types: a variant of TVRAT (also known as TeamSpy) or DarkVNC. Both malware types provided operators with remote control of infected computers and exfiltrated stolen data to command-and-control servers.The indictment, filed in June 2021, alleges that a shared document within the scheme's email account contained e-commerce login credentials and personally identifiable information for hundreds of victims. Approximately half of the infected computers were located in the U.S. Microsoft has since implemented measures to block VBA macros from untrusted internet sources by default.Source: The Hacker News
