A Russian national, extradited from Cyprus, faces U.S. charges for orchestrating a massive malware campaign via fake freelance accounts. The attack infected approximately 80,000 users using malicious Excel attachments.
- Searzhudin Tamirlanovich Aktulaev was extradited from Cyprus to the U.S.
- The hacker used 255 fake accounts on a freelance platform.
- An estimated 80,000 users were targeted via malicious Excel files.
The U.S. Department of Justice (DoJ) has formally charged Searzhudin Tamirlanovich Aktulaev, a 40-year-old Russian national, in connection with a sophisticated cyberattack campaign. Aktulaev, who was apprehended in Cyprus in May 2025, was successfully extradited to the United States on August 28 to face justice for his role in a widespread malware distribution scheme.
According to official indictments from the U.S. Attorney's Office for the Northern District of California, Aktulaev operated during 2016 and 2017. He leveraged approximately 255 fraudulent accounts on a major freelance platform to conduct his operations. By posing as legitimate freelancers, he was able to send malware-laden Excel attachments to roughly 80,000 users, compromising their digital security and potentially exposing sensitive data.
The Mechanics of the Attack
The campaign relied heavily on social engineering. By creating credible-looking profiles on a freelance marketplace, the perpetrator established a veneer of legitimacy. Once communication was established with potential clients or collaborators, the attacker would send Excel files containing malicious macros. Upon execution, these macros would download and install malware onto the victim's machine, opening backdoors for further exploitation.
Why This Matters
BozokMedia analysis shows that this case highlights a critical vulnerability in the modern digital economy: the exploitation of trust in freelance ecosystems. As remote work and gig economies expand, the surface area for identity-based attacks grows, making platform verification more crucial than ever.
The transition from brute-force hacking to identity-based deception marks a dangerous evolution in global cyber warfare.
The successful extradition of Aktulaev also underscores the increasing effectiveness of international cooperation between law enforcement agencies to combat cross-border cybercrime. This serves as a stern warning to digital criminals that geographical boundaries no longer provide sanctuary.
Historical Background
During the mid-2010s, Excel-based malware was a predominant threat vector. Because Excel is a staple in corporate environments, users often lacked the suspicion necessary to treat attachments as potential threats. This period saw a massive rise in 'macro-enabled' malware, leading to significant changes in how software companies handle file permissions.
Frequently Asked Questions
Question 1: How many people were affected by this campaign?
Answer: It is estimated that approximately 80,000 users were targeted and potentially infected.
Question 2: Where was the suspect caught?
Answer: The suspect, Searzhudin Tamirlanovich Aktulaev, was arrested in Cyprus before being extradited to the U.S.