
Aktulaev Extradited for 2016-2017 Excel Macro Campaign Delivering TVRAT and DarkVNC to 80,000 Freelance Users
Aktulaev faces multiple U.S. charges for a 2016-2017 malware campaign that infected 80,000 freelance users with TVRAT and DarkVNC via Excel macros. The technical trail—U.S. C2, victim PII cache, and DLL hijacking—contrasts with the absence of independent state-actor attribution. The case underscores persistent risk to individual users and the delayed impact of platform-level macro defenses.
The indictment details macros that fetched password-protected installers bundling signed TeamViewer binaries with a malicious msimg32.dll via DLL search order hijacking. Both TVRAT and DarkVNC beacons reported to a U.S.-hosted C2; roughly half the victims were domestic, many inside the Northern District of California. A recovered shared document contained e-commerce credentials and PII for hundreds of victims. Technical evidence shows the operators relied on TeamViewer v6 DLL hijacking first documented by Kaspersky in 2013 and later observed by Avast in 2017 samples. DarkVNC, advertised on Exploit forums in late 2016, created a hidden desktop for remote control. Microsoft’s 2022 default block of internet-sourced VBA macros directly addressed the delivery vector. The case fits a documented pattern of Russian nationals using freelance platforms for initial access, with C2 infrastructure deliberately placed in the U.S. to blend with victim callbacks. Official attribution rests on account creation logs and financial flows; independent confirmation of state direction remains absent from the unsealed filings. Aktulaev’s trial will test whether the shared credential document and C2 logs suffice for conviction on aggravated identity theft and wire fraud. Expect further indictments or MLAT requests targeting co-conspirators identified through the same infrastructure.
DOJ: Aktulaev convicted on at least two counts by end of 2027 calendar year.
Sources (3)
- [1]DOJ U.S. Attorney's Office Northern District of California Press Release(https://www.justice.gov/usao-ndca/pr/russian-national-extradited-cyprus-faces-charges-malware-campaign)
- [2]Avast Blog: TeamSpy Excel Macro Analysis(https://blog.avast.com/teamspy-malware)
- [3]eSentire: DarkVNC Technical Analysis(https://www.esentire.com/blog/darkvnc-analysis)