logo

Russian Hacker Indicted for Using Excel Malware to Target 80,000 Freelancers With TVRAT and DarkVNC

ID: b4c2b3fe-482d-54f8-b911-9bcae31d1789

STIX ID: report--b4c2b3fe-482d-54f8-b911-9bcae31d1789

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-09-02

Date Updated: 2026-09-16

Author: Tushar Subhra Dutta

...
...

A U.S. indictment alleges a Russian national led a large-scale malware campaign (June 2016–Nov 2017) that used fraudulent freelancer platform accounts and malicious Excel attachments to deliver TVRAT/TeamSpy and DarkVNC remote-access malware. Approximately 80,000 freelancers were targeted, many in the U.S.; stolen credentials and personal data were reportedly exfiltrated to command-and-control servers and later used for fraud. The defendant was arrested in Cyprus, extradited to the U.S., and remains in custody while facing multiple charges.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.