255 Fake Accounts Used to Send Malicious Excel Files to 80,000 Freelancers
ID: f7794f05-6af0-52e3-b125-0cd82ad29f5f
STIX ID: report--f7794f05-6af0-52e3-b125-0cd82ad29f5f
Feed Name: GBHackers
Federal prosecutors allege that a Russian national operated a large phishing campaign (June 2016–Nov 2017) using 255 fake freelancer accounts to send macro-laden Excel attachments to ~80,000 users on a freelance platform; executing the macros deployed TVRAT and DarkVNC remote-access malware to steal credentials, exfiltrate data to C2 infrastructure (domains paid with virtual currency), and enable follow-on fraud. The indictment, unsealed after the suspect’s extradition to the U.S., highlights how marketplace messaging can serve as a trusted initial-access vector and details victim scale, malware families, and related charges including wire fraud and computer fraud.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
