Threat Intelligence

Russian National Extradited to US Over Excel Malware Scheme That Hit Thousands of Freelancers

The Hacker News · 2 Sept 2026
Key Takeaway Be cautious with unsolicited Excel or Office attachments even from platforms where receiving files from strangers is normal, and disable macros by default unless a file's source and purpose are fully verified.

The U.S. Department of Justice has charged Searzhudin Tamirlanovich Aktulaev, 40, following his extradition from Cyprus, over an alleged malware campaign run through a freelance work platform. According to prosecutors, Aktulaev used approximately 255 fake accounts to distribute malicious Excel attachments to roughly 80,000 users on the platform between 2016 and 2017.

While details on the specific malware payload have not been disclosed, the case highlights a longstanding and still-effective attack method: disguising malicious files as legitimate business documents, such as invoices, quotes, or project files, and sending them through platforms where users expect to receive attachments from strangers. Freelance and gig-work platforms are attractive targets for this kind of abuse because interactions with unknown parties are routine and users are conditioned to open shared files quickly to win or complete work.

Aktulaev was arrested in Cyprus in May 2025 and has now been brought to the United States to face charges. The case serves as a reminder that malicious document campaigns, though not new, remain a persistent threat, particularly for small businesses and freelancers who regularly exchange files with unfamiliar clients or contractors online.

malware phishing Excel malware extradition cybercrime

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.