Russian National Charged Over Freelance Platform Malware Campaign Targeting 80,000 Users
A job offer on a freelance marketplace could end in the complete loss of control over one’s computer. U.S. authorities have accused a 40-year-old man of orchestrating a multi-year campaign whose participants dispatched malicious files to roughly 80,000 freelancers across the globe.
According to the investigation, between June 2016 and November 2017 the accused and his accomplices created around 255 counterfeit accounts on an unnamed freelance-hiring platform. Through its built-in messaging system, they sent users Microsoft Excel files. Once opened, the document prompted the victim to run a macro, which then downloaded malware from the internet. Such phishing attacks induce the victim to launch the dangerous file themselves, disguised as an ordinary work assignment.
Two Remote-Access Trojans at the Campaign’s Heart
Investigators tie the campaign to TVRAT, also known as TVSPY and TeamSpy, and to DarkVNC. Both families belong to the category of remote-access trojans. TVRAT granted the attackers control over the infected computer through TeamViewer, while DarkVNC accomplished a similar task by means of VNC Viewer. The harvested information flowed to the perpetrators’ command-and-control servers.
The scale of actual infections proved smaller than the number of lures distributed, yet it still ran into thousands of computers. One of the controlling domains, hosted in the United States, received connections from thousands of infected devices. Roughly half of the identified victims were located in the United States. The investigation also uncovered a database holding the records of thousands of victims, along with a shared document containing login credentials for e-commerce services and the personal information of hundreds of people. According to the prosecution, the stolen data was used for fraud and other crimes.
Arrest in Cyprus and Extradition to the United States
The suspect was detained on May 22, 2025, in Cyprus, where he had arrived for a relative’s wedding. His defense sought to halt the extradition to the United States, contending that the American side possessed insufficient evidence. The lawyers also invoked a statement by an accomplice, who claimed that he had allegedly committed the imputed offenses himself, without the defendant’s knowledge. The Supreme Court of Cyprus rejected the defense’s arguments.
The United States secured the extradition on August 28, 2026, and on August 31 the man first appeared before a federal court in San Francisco. According to the unsealed indictment, filed as far back as June 1, 2021, he is charged with conspiracy to commit fraud, computer fraud, unlawful acquisition of data, damage to protected computers, and aggravated identity theft.
On the most serious count, the defendant faces up to 20 years’ imprisonment. The next hearing is scheduled for October 5, 2026. The accused remains in custody, and the charges brought against him have yet to be proven in court.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.