Fake Freelancer Accounts Pushed Malicious Excel Macros

The Hacker News · Medium sophistication
Last updated September 2, 2026

U.S. prosecutors say a Russian national used hundreds of fake accounts on a freelance platform to send Excel files that tricked users into enabling macros, which then downloaded remote-control malware. The campaign targeted tens of thousands of users and led to thousands of infections, enabling credential theft and remote access to victims’ computers.

Key findings

  • Attackers allegedly used "roughly 255 fake accounts on a freelance platform" to distribute malware.
  • Messages included Excel attachments that "prompted recipients to run a macro" which then downloaded malware.
  • Two malware families were used (TVRAT/TeamSpy and DarkVNC) to enable remote control and data theft.
  • Stolen data included "e-commerce login credentials and personally identifiable information (PII)" for hundreds of victims.
  • The campaign targeted about "80,000" users and resulted in "Thousands of computers infected."

Who’s being targeted

  • Commonly targeted roles: Freelancers/Contractors, Software Developers/Engineering, Recruiting/Talent Acquisition, HR, Anyone using freelance/job platforms.
  • Affected industries: Online freelance marketplaces / employment platforms, Professional services (freelancers/contractors), Software development.
  • Attack channels: email.
  • Impersonated: A client or recruiter on a freelance platform (using a fake account).

Awareness takeaways

  • Treat unsolicited Excel attachments from new contacts as high risk, especially in job/freelance contexts.
  • Do not enable Office macros for documents received from the internet or unknown senders; use safer review methods (preview, ask for PDF, verify via the platform).
  • Remember that ‘remote access’ malware can hide in what looks like legitimate tools, enabling silent control of your device and data theft.

Red flags to watch for

  • Unexpected Excel attachment from a new/unknown platform contact
  • Pressure/instruction to enable or run macros in an Office document
  • File behavior that triggers a download from the internet after enabling macros
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine a 'new client' on a freelance site sending you an Excel file and saying, "Enable macros to see the project details." Prosecutors say someone ran roughly 255 fake freelancer accounts like this, blasting malware‑laced Excel files to about 80,000 users. The macro they enabled quietly pulled in TVRAT and DarkVNC, giving remote control of thousands of computers. Once in, those tools stole e‑commerce logins and other personal data while the screens looked totally normal. The only real clue was the setup: a brand‑new contact, an unexpected Excel, and pressure to turn macros on. If a new or untrusted contact sends an Excel and tells you to enable macros, stop and ask for a PDF or a platform message instead, do not turn macros on.

Similar attacks

Fake Recruiters Push “Coding Tests” as RAT Traps

Fake Recruiters Push “Coding Tests” as RAT Traps

Researchers say the Iran-linked group Nimbus Manticore posed as recruiters on LinkedIn and job platforms to send developers “technical challenge” ZIP files that secretly installed cross-platform remote access trojans. The lures used urgency (short test windows) and realistic developer workflows…

September 1, 2026
Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Researchers say the North Korea-linked Lazarus group ran “Operation Dream Job,” posing as recruiters and sending fake job offers to lure targets into downloading trojanized PDF tools and opening booby-trapped PDFs. The campaign focused largely on defense-related organizations and used both a…

August 12, 2026
APT42 Lures Targets With Podcast Invites

APT42 Lures Targets With Podcast Invites

Researchers report Iranian-linked APT groups using legitimate cloud services to hide command-and-control traffic, and separately running spear-phishing campaigns. In the phishing cases, attackers used credible “podcast” or “interview invitation” themes to persuade targets to open a Windows shortcut…

August 17, 2026
Fake Lockheed Jobs Used to Deliver Lazarus Zero-Day

Fake Lockheed Jobs Used to Deliver Lazarus Zero-Day

Check Point says North Korea’s Lazarus Group targeted defense and aerospace professionals using convincing fake job offers that led victims to download trojanized PDF software. The campaign used a Windows zero-day (now patched as CVE-2026-68820) to gain full control and hide from security tools,…

August 13, 2026
Fake Job Offers Spread Lazarus Zero-Day Attack

Fake Job Offers Spread Lazarus Zero-Day Attack

Researchers describe a real, ongoing Lazarus-linked campaign where targets are lured with attractive job offers and tricked into downloading a PDF viewer and “job description” documents. Opening the files installs backdoors and, in at least one wave, attackers used a Windows zero-day to gain deep…

August 11, 2026
Fake Recruiters & Cloud Email Fuel New Phishing

Fake Recruiters & Cloud Email Fuel New Phishing

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send…

September 2, 2026