Introduction
The U.S. Attorney's Office for the Northern District of California has brought formal charges against a 40‑year‑old Russian citizen for orchestrating a large‑scale phishing operation that relied on malicious Microsoft Excel files. The indictment follows an extradition from Cyprus on August 28, marking a rare instance of cross‑border cooperation in a cybercrime case that targeted tens of thousands of users.
What Happened
Searzhudin Tamirlanovich Aktulaev, arrested in Cyprus in May 2025, managed a campaign spanning 2016 and 2017. He created approximately 255 counterfeit accounts on a popular freelance‑platform marketplace. From these identities, he dispatched emails containing Excel attachments embedded with malicious code. The outreach affected an estimated 80,000 recipients, many of whom were likely professionals seeking freelance work.
Technical Details
The malicious payload was concealed within Excel files, a delivery method that exploits the trust users place in familiar office documents. By embedding malicious macros or exploiting known vulnerabilities in Microsoft Excel, the attachments could execute arbitrary code once the user enabled content. The campaign did not rely on a single exploit; instead, it leveraged the ubiquity of Excel and the social engineering advantage of a freelance‑platform context to increase click‑through rates.
Who Is Affected
Microsoft Excel is the sole product listed as affected, meaning any user who opened the tainted files on a vulnerable version of Excel was at risk. The 80,000‑person target set likely included freelancers, small‑business owners, and possibly corporate employees who use freelance platforms to source talent. While the indictment does not specify the geographic distribution of victims, the scale suggests a global reach.
Why It Matters
The case underscores two persistent challenges for defenders. First, attackers continue to weaponize trusted file formats, bypassing perimeter defenses that focus on executable binaries. Second, the use of legitimate‑looking freelance‑platform accounts demonstrates how social engineering can be amplified through reputable services. The successful extradition also signals that law‑enforcement agencies are willing to pursue international avenues to hold cybercriminals accountable.
Exploitation/Attack Information
The operation was reported as having been executed in the 2016‑2017 window. Attackers distributed the malicious Excel attachments via email, likely using bulk‑mailing tools to reach a broad audience. Recipients who opened the files and enabled macros triggered the execution of the embedded code, which could have installed backdoors, credential‑stealing modules, or ransomware. The absence of a disclosed CVE suggests the attackers may have relied on user interaction rather than a software flaw, but the exact malicious code family remains unspecified in the public filing.
Recommended Actions
Organizations should treat Excel files from unknown senders as high‑risk. Immediate steps include:
- Enforce macro‑blocking policies across the enterprise and require explicit user approval before enabling content.
- Deploy email security gateways that can sandbox and analyze Office documents for malicious behavior.
- Conduct user awareness training focused on phishing scenarios that involve freelance‑platform communications.
- Keep Microsoft Office suites patched to the latest releases, even if the attack did not exploit a known vulnerability.
- Monitor network traffic for outbound connections that may indicate successful payload execution.
Conclusion
The indictment of Searzhudin Tamirlanovich Aktulaev illustrates how a coordinated social‑engineering effort can leverage everyday tools like Excel to compromise a large user base. The cross‑jurisdictional extradition demonstrates that cybercriminals cannot rely on geographic distance to evade prosecution. Defenders must tighten controls around Office document handling and reinforce phishing awareness, especially in contexts where freelance platforms are used for recruitment.
Sources
- The Hacker News: https://thehackernews.com/2026/09/extradited-russian-hacker-faces-charges.html