Security2 distinct publishers3 min readPublished
A Northern California freelance marketplace's own messaging system carried Excel macro lures to 80,000 of its users across 18 months. Microsoft closed that delivery step in 2022. The same platform lure now shows up in North Korean operations.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Avast's April 2017 teardown of a TeamSpy sample shows where the detection problem actually sat. The macro fetched a password-protected installer that dropped legitimate, digitally signed TeamViewer binaries next to a malicious msimg32.dll, which Windows loaded in place of the real library through DLL search order hijacking; Avast noted that checking the signature on the main executable reveals nothing suspicious [15]. The library then hooked close to 50 Windows APIs so the TeamViewer window and its dialogs never appeared, and the host reported its TeamViewer ID to the C2. That ID plus a preset password is an interactive session on the machine [16].
The naming fight around that chain is not cosmetic. The DOJ release says TVRAT exploits a vulnerability in TeamViewer [12]. Kaspersky used the same word in March 2013, describing a module that "uses a vulnerability in TeamViewer v6 known as Dll-hijacking" [13]. A TeamViewer spokesman told Security Affairs in February 2017 that the company had "no evidence to assume a vulnerability of our software" [14]. Avast's description points at loading behaviour rather than a defect in the product, so there was no vendor patch for defenders to wait on, and the only reliable signals were the artifacts: a TeamViewer install nobody requested, a suppressed UI, and outbound traffic to a paid-for C2 domain [9][15][16].
The reach here comes down to simple arithmetic. 255 fake accounts, roughly 80,000 recipients, works out to about 314 messages per account across the 18 months from June 2016 to November 2017 [25][26]. That is a bulk mail run with no deliverability problem: no sending domain to get blocklisted, no target list to buy, because the platform's own user base and messaging system supplied both [5][6]. Freelancers on a hiring site open attachments from strangers because that is what the work looks like. Thousands of the infected hosts called back to a C2 domain hosted inside the United States, and about half the victims were in the country, many in the same district that indicted him [8].
The timeline is its own story. Three years and seven months separate the last alleged message from the sealed grand jury indictment [27]. Another three years and eleven months separate that filing from the airport arrest [28]. Aktulaev has denied guilt and said he was unaware of the U.S. charges, according to Russian Embassy statements in Nicosia reported by RIA Novosti and TASS [19].
A single detail pins down when the toolkit came together. DarkVNC, the hidden-desktop utility that formed the second payload, was first advertised on the Exploit forum on November 24, 2016, per eSentire, roughly five months after the campaign had already started [7][17][29]. Commodity hVNC was bolted onto a running operation. The macro step that carried both payloads has been off by default since 2022 in internet-sourced Office files [18]. The channel kept working: ESET reported in February 2025 that North Korean operators were using the same freelance-platform lure against software developers [22], and Check Point Research documented fake-recruiter campaigns last month, including a Lazarus Group wave pairing job offers with remote access malware [23].
Ranked by verification strength, evidence, and original report placement.
Searzhudin Tamirlanovich Aktulaev, 40, a Russian national, was arrested at Larnaca Airport in Cyprus in May 2025.
Aktulaev was extradited from Cyprus to the United States on August 28.
He made his initial appearance in federal court in San Francisco on August 31 and was remanded to federal custody, according to the U.S. Attorney's Office for the Northern District of California.
The indictment was filed on June 1, 2021 by a California federal grand jury and unsealed the same day as his court appearance.
From at least June 2016 through November 2017, Aktulaev allegedly used roughly 255 fake user accounts on a freelance platform to send Microsoft Excel attachments with malicious macros to about 80,000 of the platform's users; the macros downloaded malware from the internet.
The indictment describes the victim platform only as "a well-known freelance employment technology company" based in the Northern District of California.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
1 article · September 2, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Spoofed vendor download pages hand out a fresh payload hash on every click1 distinct publisher
security
Defender's SYSTEM race is back: ShieldBreak PoC says Microsoft's July fix never held6 distinct publishers
product
White House lets vetted firms hack back and leaves liability blank for 60 days1 distinct publisher
security
Cavern's DNS Coin-Flip: When Google Apps Script Becomes Rotatable C2 Plumbing1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One prosecutor's release, two rewrites, and a well-documented malware trail
Every number that matters — 255 accounts, 80,000 recipients, half the victims in the US, hundreds of sets of credentials in a shared document — comes from a single unsealed indictment and the accompanying release, and both BleepingComputer and The Hacker News say as much. Nothing has been tested in court, and the marketplace at the centre of it is anonymous and silent. What raises this above stenography is the second layer only The Hacker News builds: Kaspersky in 2013, Avast on an April 2017 sample down to the substituted msimg32.dll, eSentire on DarkVNC's forum debut. The tooling is documented by name; the man's role is still an allegation.
Scale counted by prosecutors; the lure counted by everyone since
The only measure of reach is the government's: 80,000 messages out, thousands of machines calling home to a domain hosted in the US. That is real but unaudited, and it stopped nine years ago. The stronger adoption signal is that the technique kept earning its keep after this operator allegedly stopped — ESET placed North Korean crews on the same freelance-platform approach in February 2025, and Check Point tied a Lazarus wave to fake job offers weeks before this extradition. Meanwhile the specific delivery step decayed on its own: Microsoft's 2022 default block means an Excel macro from a stranger no longer runs itself.
'Infecting 80,000' is the count of people messaged
BleepingComputer's headline says the charges cover infecting 80,000 freelancers; its own body says 80,000 were sent Excel attachments and thousands were infected. The Hacker News keeps the distinction intact — attachments to about 80,000 users — and that single word does most of the inflation in our coverage. The rest is restrained: the presumption of innocence is stated, the defendant's denial appears, and the mitigation that closed this attack path four years ago is on the page. The gap is one of framing at the top, not of substance underneath.
A prosecutor's win, a vendor's denial, and research that doubles as marketing
Follow who benefits from each line. The scale figures come from a US Attorney announcing a five-year-old sealed case finally landed, alongside a separate botnet takedown the same week. TeamViewer's flat 'no evidence to assume a vulnerability of our software' protects a product that Kaspersky and Avast both describe as the thing being abused. The technical detail arrives courtesy of four security vendors whose research is also their storefront. The denial reaches readers through the Russian Embassy in Nicosia by way of RIA Novosti and TASS. And BleepingComputer's page closes on a sponsored detection-report pitch. None of that makes the facts wrong; it does explain which facts got said out loud.
Two accounts that agree because they read the same document
Agreement between BleepingComputer and The Hacker News on dates, counts and charges is reassuring about transcription and tells us nothing about the underlying case. The procedural facts — Larnaca in May 2025, extradition on August 28, arraignment on August 31, Judge Donato on October 5 — are as solid as court records get. The attribution of an 18-month campaign to this defendant is one grand jury's view, denied by him, and nearly nine years old. Confidence sits mid-range and should stay there until the case is argued.