ThreatPaper
False

The malware campaign infected 80,000 freelancers

Assessment

80,000 is the number of platform users the indictment says "received the fake job invites" (¶19). The same paragraph gives the infection counts: "at least 2,169 computers infected with the TVRAT malware were identified to have called back to the C2 server" and "at least 1,584 computers infected with the DarkVNC malware," the latter among victims who "did not have a connection to Company A." A headline of 80,000 infected PCs multiplies the actual TVRAT infection count by roughly 37. The DOJ release, which said "thousands," did not make this error.

Where this claim appeared

Tom's Hardware · 2026-09-03

https://www.tomshardware.com/tech-industry/cyber-security/russian-hacker-faces-up-to-20-years-in-prison-following-extradition-and-indictment-over-us-phishing-campaign-that-allegedly-infected-80-000-pcs-hacker-stole-victims-data-via-remote-access

What “False” means

Contradicted by primary sources. Reserved for claims checked directly against the authoritative record — an advisory that does not exist, a catalogue that does not list the entry, a directive that says something other than what is reported.

1 of 5 · rating scale

Assessed in

The Freelance Platform That Delivered TeamSpy: 80,000 Job Invites, 2,169 Infections, One Extradition

Think this assessment is wrong? Report an error.