[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fmYqMJQYj0cKacB0uoptAhrtqE_gQ1gpNgBoOnQvBczY":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"01248496-e885-4d4c-b6ba-b78b02aea7c2","fake-freelancer-accounts-used-to-spread-excel-malware-to-80000-victims","1a898852-96b5-4bf9-85bc-c30bfc23750f","Fake Freelancer Accounts Used to Spread Excel Malware to 80,000 Victims","Aktulaev exploited the inherent trust users place in freelance platforms by creating fraudulent accounts to distribute malicious Excel attachments, demonstrating how social engineering can bypass technical defenses at scale. The use of macro-enabled Office documents as a delivery vector remains one of the most effective and persistent attack methods because many users open attachments without verifying their source or content. Once installed, TVRAT and DarkVNC granted attackers persistent remote access, meaning compromised systems could be exploited long after initial infection. This case underscores the critical importance of user education around file attachments, platform vetting of accounts, and endpoint controls that restrict dangerous macro execution.","**Immediate actions:**\n- Disable or restrict Microsoft Office macro execution by default via Group Policy for all non-essential users.\n- Enforce multi-factor authentication on all freelance, vendor, and third-party platform accounts used by your organization.\n\n**Detection measures:**\n- Deploy endpoint detection and response (EDR) tools configured to alert on known RAT behaviors such as TVRAT and DarkVNC signatures.\n- Monitor outbound network traffic for connections to unusual or newly registered domains that may indicate C2 communication.\n\n**Long-term improvements:**\n- Conduct regular security awareness training focused on recognizing phishing and malicious attachment campaigns, including simulated exercises.\n- Establish a vetting and approval process for any third-party or freelance contributors who interact with organizational systems or share files.\n- Implement application allowlisting to prevent unauthorized executables from running on endpoints.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 9: Email and Web Browser Protections","CIS Control 14: Security Awareness and Skills Training","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-53 AC-2: Account Management","NIST SP 800-53 AT-2: Security Awareness Training","NIST SP 800-53 SC-7: Boundary Protection","MITRE ATT&CK T1566.001: Phishing – Spearphishing Attachment","MITRE ATT&CK T1219: Remote Access Software","GDPR Article 32: Security of Processing","published","2026-09-02T10:20:51.059478+00:00","2026-09-02T10:20:50.783+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fextradited-russian-hacker-faces-charges.html","extradited-russian-hacker-faces-charges-over-excel-malware-campaign-that-infecte-eb3bb0","Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":37,"name":38,"slug":39,"description":40,"color":41},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":43,"name":44,"slug":45,"description":46,"color":47},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]