In short: Russian national Searzhudin Aktulaev was extradited to the United States and faces federal charges for infecting approximately 80,000 freelance platform users with TVRAT and DarkVNC remote-access trojans between 2016 and 2017, using malicious Excel files disguised as job-offer documents. The case illustrates how attackers exploit professional trust rather than obvious spam.
What happened
On September 3, 2026, the US Department of Justice unsealed an indictment originally filed in June 2021 in the Northern District of California. According to the indictment, Aktulaev created approximately 255 fake accounts on a major freelance platform and sent malicious Excel files to prospective victims, presenting them as contract terms or project briefs. He was detained in Cyprus in May 2025 and extradited to the United States on August 28, 2026.
How TVRAT and DarkVNC worked
Opening the Excel file triggered an embedded macro that silently downloaded and launched two malware tools:
- TVRAT (also known as TVSPY and TeamSpy) — hijacks the TeamViewer application to give the attacker full remote access to the victim's machine with no visible indication.
- DarkVNC — creates a hidden virtual desktop session, allowing the attacker to operate on the victim's computer without opening any visible interface windows.
Both tools transmitted data to the attacker's command-and-control server and were used to steal credentials, payment information, and personal data.
Scale and victims
According to the indictment, around 80,000 users across multiple countries received the malicious files — approximately half based in the United States. The specific platform is not named in official documents, but analysts widely identify it as Upwork, the largest freelance marketplace headquartered in Northern California. Aktulaev faces charges of conspiracy, intentional damage to computers, unauthorized access, and aggravated identity theft, carrying a maximum combined sentence of approximately 20 years.
Why this matters for remote workers
This attack is a textbook example of spear phishing: victims did not click suspicious links from spam — they opened files in what appeared to be normal professional communication with a new employer. The absence of any suspicious context is precisely what makes this vector so effective.
Once access was established via TeamViewer, attackers could browse and download any files, capture banking credentials, install additional malware, and use the compromised machine to launch attacks on the victim's own clients. Encrypting your traffic with a VPN does not prevent infection from a document, but makes it significantly harder for an attacker to intercept network data after compromise — banking sessions, corporate traffic, and transmitted passwords stay hidden inside the encrypted tunnel.
How to protect yourself from document-based RAT attacks
- Disable macros by default in Microsoft Office. Modern Office versions already block macros from internet-sourced files — make sure this has not been turned off manually.
- Open unfamiliar files in the cloud: Google Docs or Microsoft 365 Online will not execute malicious macros on your device.
- Never install TeamViewer or AnyDesk at a new employer's request: legitimate clients do not need remote access to your PC during a hiring process or test task.
- Verify the prospective employer: request a video call, find the company on LinkedIn, and confirm its legitimacy before opening any attachments.
Learn how a VPN protects your data while working online in the LiMP VPN blog.
