U.S. prosecutors say a Russian national used hundreds of fake accounts on a freelance platform to send Excel files that tricked users into enabling macros, which then downloaded remote-control malware. The campaign targeted tens of thousands of users and led to thousands of infections, enabling credential theft and remote access to victims’ computers.
Key findings
- Attackers allegedly used "roughly 255 fake accounts on a freelance platform" to distribute malware.
- Messages included Excel attachments that "prompted recipients to run a macro" which then downloaded malware.
- Two malware families were used (TVRAT/TeamSpy and DarkVNC) to enable remote control and data theft.
- Stolen data included "e-commerce login credentials and personally identifiable information (PII)" for hundreds of victims.
- The campaign targeted about "80,000" users and resulted in "Thousands of computers infected."
Who’s being targeted
- Commonly targeted roles: Freelancers/Contractors, Software Developers/Engineering, Recruiting/Talent Acquisition, HR, Anyone using freelance/job platforms.
- Affected industries: Online freelance marketplaces / employment platforms, Professional services (freelancers/contractors), Software development.
- Attack channels: email.
- Impersonated: A client or recruiter on a freelance platform (using a fake account).
Awareness takeaways
- Treat unsolicited Excel attachments from new contacts as high risk, especially in job/freelance contexts.
- Do not enable Office macros for documents received from the internet or unknown senders; use safer review methods (preview, ask for PDF, verify via the platform).
- Remember that ‘remote access’ malware can hide in what looks like legitimate tools, enabling silent control of your device and data theft.
Red flags to watch for
- Unexpected Excel attachment from a new/unknown platform contact
- Pressure/instruction to enable or run macros in an Office document
- File behavior that triggers a download from the internet after enabling macros
Read the video transcript
Imagine a 'new client' on a freelance site sending you an Excel file and saying, "Enable macros to see the project details." Prosecutors say someone ran roughly 255 fake freelancer accounts like this, blasting malware‑laced Excel files to about 80,000 users. The macro they enabled quietly pulled in TVRAT and DarkVNC, giving remote control of thousands of computers. Once in, those tools stole e‑commerce logins and other personal data while the screens looked totally normal. The only real clue was the setup: a brand‑new contact, an unexpected Excel, and pressure to turn macros on. If a new or untrusted contact sends an Excel and tells you to enable macros, stop and ask for a PDF or a platform message instead, do not turn macros on.