Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Malicious Content. Show all posts

Russian National Charged Over Malware Campaign Targeting 80,000 Freelancers

 


A Russian national has been extradited to the United States to face federal charges over an alleged malware campaign that targeted approximately 80,000 users of a freelance employment platform.

Searzhudin Tamirlanovich Aktulaev, 40, is accused of using hundreds of fraudulent accounts to distribute malicious Microsoft Excel attachments between June 2016 and November 2017. Prosecutors allege that the attachments downloaded remote-access malware capable of controlling victims’ computers and stealing information.

The indictment was filed under seal on June 1, 2021. Aktulaev was arrested in Cyprus in May 2025 and extradited to the United States on August 28, 2026, according to the US Department of Justice.

He appeared in federal court in San Francisco on August 31 and was remanded to federal custody. The indictment was unsealed the same day.

Fake Freelance Accounts Distributed Malicious Excel Files

According to prosecutors, Aktulaev and his alleged co-conspirators exploited the messaging system of a well-known freelance employment technology company located in California’s Northern District.

The DOJ did not publicly identify the company.

The conspirators allegedly created approximately 255 fake user accounts and used them to send messages containing malicious Excel attachments to around 80,000 freelancers.

Opening an attachment prompted the recipient to enable or execute an embedded macro. If the user complied, the macro downloaded malware from the internet.

This distinction is important: the indictment alleges that malware was distributed to approximately 80,000 users, but the DOJ announcement does not establish that every recipient opened the attachment or became infected.

Freelancers can be particularly exposed to attachment-based attacks because their work routinely involves receiving documents from unfamiliar prospective clients. A spreadsheet presented as a project brief, financial record or work assignment may therefore appear consistent with an ordinary business request.

TVRAT and DarkVNC Provided Remote Access

The indictment identifies two malware families allegedly used in the campaign: TVRAT and DarkVNC.

TVRAT, also known as TVSPY or TeamSpy, incorporated or abused components associated with TeamViewer, a legitimate remote-administration product. DarkVNC provided similar hidden remote-control capabilities using Virtual Network Computing technology.

Prosecutors allege that the malware allowed the conspirators to control infected computers and transfer stolen data to command-and-control servers.

The use of recognizable remote-access components can help criminals disguise malicious activity as legitimate administrative traffic. It can also make detection more difficult when organizations permit remote-support products in their environments.

The allegations do not indicate that TeamViewer or VNC Viewer participated in the operation. The case concerns malware that allegedly misused remote-administration technology.

Thousands of Computers Connected to US-Based Infrastructure

Court allegations state that domains supporting the command-and-control infrastructure were purchased using virtual currency. At least one command-and-control domain was hosted in the United States, and thousands of computers infected with TVRAT reportedly connected back to it.

Investigators discovered a database on the command-and-control infrastructure containing information associated with thousands of victims.

The DOJ also said a shared document stored in an email account used during the alleged criminal activity contained e-commerce login credentials and personally identifiable information belonging to hundreds of people.

Prosecutors allege that information stolen through TVRAT and DarkVNC was collected from the command-and-control servers and used by Aktulaev and his co-conspirators to conduct fraud and other criminal activity.

Approximately half of the identified victims were located in the United States. The DOJ said many—not all—of those US victims were in the Northern District of California, where the federal case is being prosecuted.

Aktulaev Faces Multiple Federal Charges

The indictment charges Aktulaev with conspiracy, aggravated identity theft and transmitting code or commands that caused damage to protected computers. It also includes allegations involving wire fraud, unauthorized computer access and obtaining information or value from compromised systems.

The most serious listed offense, conspiracy to commit wire fraud, carries a maximum potential sentence of 20 years in prison. A charge involving intentional damage to protected computers carries a maximum of 10 years, while aggravated identity theft can result in a mandatory consecutive two-year sentence for each conviction.

These are maximum statutory penalties rather than a predicted sentence. Any punishment would depend on which charges, if any, result in conviction and the federal court’s consideration of applicable sentencing rules.

Aktulaev is scheduled to appear before US District Judge Donato on October 5, 2026, for a status conference.

The FBI investigated the case, which is being prosecuted by the National Security, Cyber, and Special Prosecutions Section of the US Attorney’s Office for the Northern District of California. The Justice Department’s Office of International Affairs secured the extradition from Cyprus.

The Campaign Predates Aktulaev’s Arrest

The alleged campaign operated from 2016 to 2017. The indictment was filed in 2021, approximately four years after the campaign ended—not four years after Aktulaev’s arrest.

Aktulaev was arrested in Cyprus in May 2025 and extradited more than a year later. The DOJ has not explained why the indictment remained under seal or provided details about the extradition proceedings.

Because the case is at the indictment stage, all described conduct remains an allegation. Aktulaev is presumed innocent unless prosecutors prove the charges beyond a reasonable doubt.

Security Analysts Observe Massive Surge in Telegram App Downloads Following Durov Arrest

 

The arrest of Telegram creator and CEO Pavel Durov in France is beginning to have an influence on the app's popularity and position.

The founder was arrested last month for allegedly allowing illicit practices to thrive on the social media platform by failing to properly monitor posts, particularly in drug trafficking, money laundering, and the spread of child sexual abuse material (CSAM). 

Despite concerns regarding the app's content, Telegram is now experiencing a spike in downloads, propelling it to the No. 2 spot on the U.S. App Store's Social Networking charts and increasing global iOS downloads by 4%. 

After Durov's arrest, Telegram took some time to rise. This might be the case because a lot of individuals found out about the news only after reading the stories they had missed over the weekend, or because third-party sources of app store intelligence take a little longer to report changes in rankings. 

According to Appfigures, an app intelligence company, Telegram didn't rise to the No. 2 spot on the Social Networking charts on the U.S. App Store until 3 a.m. EST on Monday, suggesting that the app is just now starting to gain traction. The app had already fallen to No. 3 in Social in the U.S. as of the time of publication, so it might only be a temporary boost.

However, the app shot to the top of the App Store's Social Networking category and rose to become the third most popular app overall in France, the country where Durov was arrested. After climbing ten spots since Friday, Telegram now stands at No. 8 in the top apps chart (which does not include games). Appfigures stated that this is the highest position it has held here since at least January 1, 2023. Apple often uses a combination of measures, including download velocity and app install count, to determine app store rankings.

Nevertheless, the cliché "any press is good press" appears to hold true, at least in terms of Telegram's exposure on the App Store. As consumers downloaded the app out of curiosity — or possibly to support the founder's views about "free speech" — it began to rise in the rankings.

Indonesia Bans Search Engine DuckDuckGo

 

Bad news for anyone concerned about their privacy who lives in or plans to visit Indonesia in the near future. As authorities ramp up their efforts to combat illegal online gambling and pornography, online privacy suffers as a result. DuckDuckGo, a private search engine, is the first casualty. 

On Friday, August 2, 2024, government officials told Reuters that the safe search engine had been disabled due to increasing complaints about online gambling and pornography content in its search results. According to local reports, the government intends to restrict access to free VPN services as part of a nationwide crackdown on criminal online activities. 

Privacy at risk 

As mentioned before, DuckDuckGo is a privacy tool that millions of individuals across the world use every day to browse anonymously and secure their private data. Enforcing a ban on its use deprives people who reside in or travel to Indonesia of a useful tool for protecting their online privacy. 

Access to the top VPN apps is also at risk, which is a recipe for disaster in terms of privacy. A virtual private network (VPN) is a type of security software that encrypts your internet connections and masks your IP address location. While both functions increase your online privacy, the latter also allows you to access geo-restricted content. 

This means you may not be able to use a streaming VPN to continue viewing your favourite TV series when travelling across the country. Worse, citizens and travellers will be unable to circumvent the current internet limitations. Indonesia, home to the world's biggest Muslim population, has strong restrictions against sharing unlawful or obscene online information. This is why, in addition to gambling and pornographic websites, social media platforms such as Reddit and Vimeo have been blocked. 

Given that the ban on free VPNs is not in effect at the time of writing, using a VPN remains the easiest way to circumvent internet restrictions and continue using DuckDuckGo, Reddit, and any other services that are currently banned. 

After you've downloaded your preferred app, all you have to do is connect to a server outside of the country - security experts suggest one in a region where internet access is unrestricted. This will trick your internet service provider (ISP) into believing you are in the same location as the server and, as a result, allow you access.