ThreatPaper
MalwareSocial EngineeringFinancial FraudMedium

The Freelance Platform That Delivered TeamSpy: 80,000 Job Invites, 2,169 Infections, One Extradition

By pico picu · 12 Sept 2026 · 17 min read

Threat Actor: Serazhudin Tamirlanovich Aktulaev (charged, presumed innocent) and a co-defendant whose name is redacted; case captioned United States v. Soltymuradov · Target: ~80,000 users of a Santa Clara-based freelance employment platform ("Company A"), June 2016 – February 2017; a separate set of DarkVNC victims, May – November 2017

Source: www.justice.gov


Executive Summary

On 31 August 2026 a Russian national, Serazhudin Tamirlanovich Aktulaev, 40, made his first appearance in the US District Court for the Northern District of California, three days after his extradition from Cyprus, where he had been held since May 2025. An indictment returned by a federal grand jury on 1 June 2021 and sealed until that day charges him and a co-defendant, whose name is redacted from the public filing, with six counts: conspiracy to commit computer fraud, conspiracy to commit wire fraud, three substantive Computer Fraud and Abuse Act offences, and aggravated identity theft. He is in federal custody, has entered a plea of not guilty according to the Russian Embassy, and is due before Judge James Donato on 5 October 2026. An indictment alleges; nothing below is proven.

The alleged scheme is a textbook of its era. Between June and August 2016 the defendants created at least 225 fake accounts on "Company A," described only as a freelance-employment platform based in Santa Clara, California, and used them to send fictitious job invitations to roughly 80,000 legitimate freelancers. Each invitation carried a Microsoft Excel spreadsheet with a hidden macro. Opening the file and enabling the macro fetched TVRAT, the TeamViewer remote-access trojan known since 2013 as TeamSpy, which installs a genuine, signed copy of TeamViewer alongside a malicious msimg32.dll and gives the operator silent remote control. The indictment says 2,169 infected machines beaconed to the command-and-control domain pushatone[.]net, about 1,000 of them in the United States and 46 in the Northern District of California. Harvested credentials went into an SQL database the defendants built, and from there into fraudulent transactions on victims' accounts. A second campaign, from May to November 2017, distributed DarkVNC, a hidden-VNC tool, from leased virtual private servers as a file named apivn.exe to victims "who did not have a connection to Company A"; 1,584 machines beaconed to a separate C2 registered in the Netherlands. The aggravated-identity-theft count rests on one Northern District victim, "L.G.," whose PayPal and Amazon passwords were used for purchases in September 2017.

The press release and the indictment disagree on the first number a reader meets. The release says "approximately 255 fake user accounts"; the indictment says "at least 225." Every outlet carried 255. The release says "thousands of computers" were infected and "approximately half of the victims were in the United States"; the indictment gives 2,169 and 1,000, which is 46%. It also spells the defendant's first name "Searzhudin," where the indictment and the court docket have "Serazhudin." These are small errors, but they are the errors a citation inherits, and the primary document was available to anyone who looked at the docket.

Two things about the case are unusual. The indictment was under seal for five years and three months, from June 2021 to the day of the initial appearance; the Russian Embassy says Aktulaev was unaware of the charges until his arrest in Cyprus. And the case is captioned United States v. Soltymuradov, after the co-defendant, whose name the Justice Department redacted from the indictment it released and omitted from its announcement. The campaign itself, meanwhile, is a nine-year-old technique with a live descendant: the same freelance-platform lure, delivered by fake recruiters with malicious attachments, is the current tradecraft of North Korean IT-worker and "Contagious Interview" operations, which is why a 2016 case is worth reading in 2026.

Verification of Claims

  1. Claim: Aktulaev was extradited from Cyprus on 28 August 2026 and appeared in court on 31 August. → Verified → DOJ N.D. Cal. release, 1 September 2026: "The Justice Department's Office of International Affairs secured the August 28, 2026 extradition"; "Yesterday, he made his initial appearance." Docket 3:21-cr-00229-JD, entries of 31 August (arraignment, interpreter, speedy-trial order).

  2. Claim: 255 fake accounts were used. → Superseded by the primary document → DOJ release: "approximately 255 fake user accounts." Indictment ¶21(c): "registered and created at least 225 fake accounts." Both documents come from the same office; the indictment is the charging instrument.

  3. Claim: About 80,000 freelancers received the malicious invitations. → Verified as alleged → Indictment ¶19: "Approximately 80,000 of Company A's users received the fake job invites."

  4. Claim: Thousands of computers were infected. → Verified as alleged, with figures → Indictment ¶19: "at least 2,169 computers infected with the TVRAT malware were identified to have called back to the C2 server," ~1,000 in the US, 46 in N.D. Cal.; "at least 1,584 computers infected with the DarkVNC malware" called back to a separate C2.

  5. Claim: The platform was Upwork. → Unverified → Neither the release nor the indictment names it. The indictment says Company A was "based in Santa Clara, California" and provided "a means of posting job listings." Upwork moved its headquarters from Mountain View to Santa Clara in 2019, before the June 2021 indictment. No other freelance platform of that size is based there. ThreatPaper draws no conclusion the documents do not.

  6. Claim: TVRAT exploits a vulnerability in TeamViewer. → Partially verified — the indictment's wording, not the mechanism → Indictment ¶8: "designed to exploit a vulnerability in the popular remote administration tool TeamViewer." Avast's April 2017 analysis of TeamSpy describes no vulnerability: legitimate signed TeamViewer binaries are installed with a malicious msimg32.dll loaded through DLL search-order hijacking. TeamViewer is abused, not exploited.

  7. Claim: The DarkVNC victims were freelancers on the same platform. → False → Indictment ¶18: "It appears these victims did not have a connection to Company A." DarkVNC was distributed from leased VPSs, not through job invites.

  8. Claim: The defendant's name is Searzhudin Aktulaev. → Superseded → The release spells it "Searzhudin"; the indictment (every count) and the CourtListener docket spell it "Serazhudin." The court's spelling is used here.

  9. Claim: Aktulaev denies the charges. → Verified as reported → The Hacker News, citing the Russian Embassy: he "denies guilt" and "was unaware of U.S. charges." A not-guilty plea at arraignment is standard and is recorded on the docket as "Plea Entered" without the plea itself being public.

  10. Claim: The indictment was sealed for five years. → Verified → Filed 1 June 2021; release: "unsealed yesterday" (31 August 2026). Docket entries 9 and 10 of 2 September are a sealing motion and order, consistent with the redacted co-defendant.

Timeline

Date Actor Event Source
March 2013 CrySyS Lab; Kaspersky First public analyses of TeamSpy, a TeamViewer-abusing espionage toolkit. Avast 2017
26 May 2016 Defendants Register C2 domain pushatone[.]net through a registrar headquartered in Milwaukee. Indictment ¶21(a)
6 June 2016 Defendants Point pushatone[.]net at a network provider with servers in Utah. Indictment ¶21(b)
June–August 2016 Defendants Create at least 225 fake accounts on Company A. Indictment ¶21(c)
June 2016 – February 2017 Defendants Send thousands of job invites with Excel macro attachments to Company A users; C2 collects credentials from infected machines. Indictment ¶21(d)–(f)
25 July 2016 Defendant Leases several VPSs with servers in New York. Indictment ¶21(h)
24 November 2016 DarkVNC author DarkVNC first advertised (per The Hacker News, citing prior research). THN
29 November 2016 Victim 1 Opens a fake job invite; machine beacons to C2 until 25 December. Indictment ¶21(d)–(e)
13 April 2017 Avast Publishes analysis of a TeamSpy variant spread by Excel macro: signed TeamViewer plus malicious msimg32.dll. Avast
9 May 2017 Defendants Register DarkVNC C2 with a cloud provider with servers in the Netherlands. Indictment ¶21(i)
May – November 2017 Defendants Distribute apivn.exe (DarkVNC) from VPSs; 1,584 machines beacon. Indictment ¶19, ¶21(j)–(k)
August 2017 Defendants Shared document created to log harvested credentials, including Victim 2 (L.G.). Indictment ¶21(l)
September 2017 Defendants or others L.G.'s PayPal and Amazon accounts used for fraudulent purchases. Indictment ¶21(m), Count Six
1 June 2021 Grand jury, N.D. Cal. Indictment returned, sealed. Indictment; DOJ
May 2025 Cypriot authorities Aktulaev arrested in Cyprus. DOJ
28 August 2026 DOJ OIA; Cyprus Extradition to the United States. DOJ
31 August 2026 N.D. Cal. Indictment unsealed; initial appearance and arraignment before Magistrate Judge Hixson; remanded; speedy-trial time excluded to 5 October. DOJ; docket
1 September 2026 USAO N.D. Cal. Press release. DOJ
2 September 2026 N.D. Cal. Redacted indictment filed as Document 8; sealing motion and order (Documents 9–10). Docket
5 October 2026 Judge Donato Status conference. DOJ

Attack Anatomy

Loading diagram...

Stage 1: the platform as delivery channel

A freelance marketplace is built to let strangers send work to strangers. A job invitation from a new client, with an attached brief or spreadsheet, is not an anomaly on such a platform; it is the product. The defendants are alleged to have created accounts in bulk over a summer and used the platform's own messaging to reach 80,000 users, each of whom had opted in to receiving exactly this kind of message. The indictment calls it spear-phishing; the platform did the targeting.

Stage 2: the macro

The attachments were "variously named Microsoft Excel spreadsheets that contained hidden malicious macros." On opening, the user was prompted to enable macros, and the macro downloaded the malware. Avast's 2017 analysis of a TeamSpy sample delivered this way describes the payload as a password-protected Inno Setup installer.

Stage 3: TVRAT / TeamSpy

The installer drops a set of legitimate, digitally signed TeamViewer binaries plus two files that are not TeamViewer's: tvr.cfg, the configuration, and msimg32.dll, the malware. msimg32.dll is a real Windows library; TeamViewer loads it by name, and Windows searches the application directory first, so the malicious copy is loaded instead of the system one. From inside TeamViewer's process the DLL hides the client's window and tray icon, reads the ID and password, and reports them to the C2. The operator then connects with TeamViewer's own infrastructure, which is why the indictment can describe the traffic without describing an exploit: the "vulnerability" is that TeamViewer runs whatever msimg32.dll it finds beside it.

TeamSpy was first documented by CrySyS Lab and Kaspersky in March 2013 as an espionage toolkit. By 2016 it had been repurposed for financial fraud; the indictment's C2, pushatone[.]net, was registered in May 2016, a month before the fake-account creation began.

Stage 4: harvest and cash-out

Infected machines beaconed to the C2; the operators collected "means of identification and financial credentials" and logged them in an SQL database they built for the purpose. The DOJ release adds that the C2 held a victim database of "thousands," and that a shared document in the email account used for the scheme contained e-commerce logins and PII for "hundreds." The identity-theft count is specific: L.G.'s PayPal and Amazon usernames and passwords, used for purchases in September 2017. Beyond that one victim's reported loss, no aggregate figure is alleged.

The second campaign: DarkVNC

From July 2016 the indictment describes leased VPSs in New York, and from May 2017 a second C2 in the Netherlands. The VPSs served apivn.exe, identified as DarkVNC, a hidden-VNC remote-access tool that eSentire analysed in 2024 and that The Hacker News dates to a first advertisement on 24 November 2016. These victims, 1,584 of them, "did not have a connection to Company A," and the indictment does not say how they were reached. The cash-out was the same: credentials into a shared document, then fraud.

Yield

80,000 invitations produced 2,169 confirmed TVRAT infections, a 2.7% conversion from message to running implant, on a platform where the message was expected and the attachment was the point.

Accused

  • Serazhudin Tamirlanovich Aktulaev, 40, Russian national. Arrested Cyprus, May 2025; extradited 28 August 2026; in federal custody. Charged on all six counts. Presumed innocent. The Russian Embassy states he denies the charges.
  • Co-defendant, name redacted in the public indictment and omitted from the DOJ release. The case is captioned United States v. Soltymuradov, so the first-named defendant is not Aktulaev. No public information on that person's status; the redaction and the 2 September sealing order are consistent with a defendant not in custody.
  • Charges and maximums (penalty sheet): Count 1, 18 U.S.C. §371, 5 years; Count 2, §1349, 20 years; Count 3, §1030(a)(2)(C), 5 years; Count 4, §1030(a)(4), 5 years; Count 5, §1030(a)(5)(A), 10 years; Count 6, §1028A(a)(1), 2 years consecutive. Fines of $250,000 or twice the gain or loss per count; forfeiture.
  • Court: N.D. Cal., 3:21-cr-00229-JD, Judge James Donato; prosecuted by the National Security, Cyber, and Special Prosecutions Section; investigated by the FBI (SAC Scott R. Schelble).
  • Tradecraft as alleged: bulk fake-account creation on a legitimate service; social-engineering lure native to that service; macro-armed Office documents; abuse of a signed remote-administration tool; US-hosted C2 for the primary campaign; separate VPS infrastructure and a second tool for a second campaign.
  • MITRE ATT&CK techniques (verified on attack.mitre.org, 12 September 2026):
    • T1585.001 Establish Accounts: Social Media Accounts (fake platform accounts)
    • T1583.001 Acquire Infrastructure: Domains; T1583.003 Virtual Private Server
    • T1566.003 Phishing: Spearphishing via Service
    • T1204.002 User Execution: Malicious File; T1059.005 Visual Basic (macro)
    • T1574.001 Hijack Execution Flow: DLL (msimg32.dll)
    • T1219 Remote Access Tools (TeamViewer, VNC)
    • T1555.003 Credentials from Web Browsers (as alleged harvesting)
    • T1071.001 Application Layer Protocol: Web Protocols
    • T1657 Financial Theft

Technical Indicators

# From the indictment (2016–17 infrastructure, historical) and Avast's 2017
# TeamSpy analysis. Defanged. None of this is current.
c2_domains:
  tvrat: pushatone[.]net          # registered 2016-05-26; hosted in Utah from 2016-06-06
  darkvnc: <redacted in indictment>   # registered 2017-05-09, cloud provider with NL servers
infrastructure:
  vps: several, leased 2016-07-25, servers in New York (DarkVNC distribution)
files:
  darkvnc_dropper: apivn.exe
  teamspy_config: tvr.cfg
  teamspy_payload: msimg32.dll     # malicious DLL beside signed TeamViewer binaries
lure:
  channel: freelance platform job invitation from a new account
  attachment: .xls/.xlsm with macro; prompts to enable content
technique_notes:
  - TeamViewer binaries are genuine and signed; detection is on the sideloaded DLL
  - Hidden VNC: no visible session on the victim desktop
victims_alleged:
  invited: ~80,000
  tvrat_beacons: 2,169 (≈1,000 US; 46 N.D. Cal.)
  darkvnc_beacons: 1,584
ip_addresses: []
file_hashes: []                  # none in the public filing

Charges. Six counts, filed 1 June 2021 under seal in the Northern District of California. Counts 1–5 are conspiracy and CFAA offences; Count 6 is aggravated identity theft, which carries a mandatory two-year consecutive term on conviction. Two forfeiture allegations attach.

Extradition. Arrest in Cyprus in May 2025; extradition on 28 August 2026 secured by the DOJ Office of International Affairs. The Cypriot proceedings are not public. Fifteen months from arrest to surrender is within the usual range for a contested extradition to the United States.

Proceedings. Initial appearance and arraignment on 31 August 2026 before Magistrate Judge Thomas S. Hixson, with an interpreter; remanded; time excluded under the Speedy Trial Act to 5 October (Document 6). Redacted indictment filed 2 September as Document 8 with a sealing motion granted the same day (Documents 9–10). Status conference before Judge Donato on 5 October.

Co-defendant. Named only in the caption. The government's decision to redact the name from a filing that is otherwise public is the clearest signal that the second defendant has not been arrested.

Platform. Company A is not named and has made no statement. The indictment treats its servers as protected computers and its users as victims; no allegation is made against it.

Prior public warning. The technique was public throughout: TeamSpy analyses from 2013, Avast's macro-delivered variant in April 2017, and platform-level reporting on fake-recruiter lures since. Nothing in the record suggests the campaign relied on anything undisclosed.

Impact Assessment

  • Invitations sentAlleged. ~80,000.
  • TVRAT infectionsAlleged, specific. 2,169 beaconing hosts; ~1,000 US; 46 N.D. Cal.
  • DarkVNC infectionsAlleged, specific. 1,584 beaconing hosts; at least one in N.D. Cal.
  • Credentials harvestedAlleged. "Thousands" in the C2 database; "hundreds" of e-commerce logins and PII records in a shared document.
  • Financial lossUnknown. One victim (L.G.) reported losses; no aggregate is alleged. Forfeiture is sought for "a sum of money equal to the total amount of proceeds," unquantified.
  • DurationAlleged. May 2016 – November 2017.
  • ConvictionNone. Indictment only.
  • Co-defendantUnknown status.

Lessons and Defensive Recommendations

For freelancers and anyone hired through a platform

  • A job invitation with a spreadsheet you must "enable content" to read is the attack, not the job. Nine years on, the lure is unchanged: fake recruiters on LinkedIn and freelance sites, an attachment or a "coding test," a request to run something. Treat enabling macros or running a repository from a new contact as handing over the machine.
  • Remote-administration tools are the payload of choice because they are signed, allow-listed and look like support. If TeamViewer, AnyDesk or a VNC server appears on your machine and you did not install it, assume compromise.

For platforms

  • 225 accounts created in a summer, each sending job invites with the same attachment type to thousands of users, is a pattern the platform's own data could have surfaced. Bulk-account velocity, attachment-type anomalies on first-message invites, and macro-bearing Office files in first contact are all detectable at the service layer.
  • The current North Korean "Contagious Interview" and IT-worker operations use the same channel. The 2016 case is the template.

For defenders

  • Block or quarantine macro-enabled Office attachments at the mail and messaging boundary; Microsoft's default block on internet-sourced macros (2022) post-dates this campaign by six years.
  • Detect remote-admin tools by sideloaded-DLL behaviour, not by binary signature: a signed TeamViewer that loads msimg32.dll from its own directory is the indicator.
  • Hidden-VNC variants leave no visible session. Watch for VNC listeners and outbound connections from processes that should not have them.

For readers of press releases

  • The indictment said 225; the release said 255. The indictment said 2,169 and 1,584; the release said "thousands." The indictment separated two campaigns; the release merged them. The primary document was one docket lookup away.

Sources

  1. US Department of Justice, USAO Northern District of California. "Russian National Indicted For Exploiting Online Platform Used For Freelance Employment And Distributing Malware To Thousands Of Victim Users Worldwide For Financial Gain". 1 September 2026.
  2. United States v. Soltymuradov, N.D. Cal. 3:21-cr-00229-JD. Redacted indictment as to Serazhudin Tamirlanovich Aktulaev, Document 8, filed 2 September 2026 (indictment dated 1 June 2021). Hosted by ISMG.
  3. CourtListener. United States v. Soltymuradov, docket 3:21-cr-00229. Entries of 31 August – 8 September 2026.
  4. Jaromír Hořejší, Avast. "A deeper look into malware abusing TeamViewer". 13 April 2017.
  5. The Hacker News. "Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands". September 2026.
  6. BleepingComputer. "US charges Russian for infecting 80,000 freelancers with malware". September 2026.
  7. Help Net Security. "Russian man indicted for spreading malware to 80,000 freelancers". 3 September 2026.
  8. Bank Info Security. "Breach Roundup: FBI Probes Sale of 153 Million Driver's Licenses". September 2026.
  9. MITRE ATT&CK. T1566.003; T1574.001; T1219; T1585.001. Accessed 12 September 2026.
Original Incident Report →

Related Research

A Russian web developer extradited from Georgia faces trial over a 2023–25 operation that bought search ads impersonating banks, harvested 5,000+ logins and 2FA codes on cloned pages, and tried to wire $5.58 million from one Atlanta company in a day. The mule LLC was registered in Georgia two months

Financial FraudSocial EngineeringIdentity Theft

A classified Customs directive published by Netzpolitik shows German agencies link a police computer to a suspect's messenger account using the apps' own multi-device feature. The BGH ruled in January that seizing chat history this way is unlawful; the directive, dated a month later.

Social Engineering

ShinyHunters says it vished McKesson employees, took over Okta sessions, and pulled a terabyte from Salesforce and Snowflake between 20 and 25 August 2026. McKesson has confirmed exfiltration of patient data and nothing about how.

Data BreachExtortion & BlackmailSocial Engineering