Connect with us

Infosecurity

Russian national faces 20 years for malware campaign that infected 80,000 freelancers

Published

on

malware campaign

Malware campaign targeted freelancers with poisoned Excel files

A Russian national is staring down a potential 20-year prison sentence after being indicted for a malware campaign that infected more than 80,000 freelancers back in 2016.

Searzhudin Tamirlanovich Aktulaev made his first appearance in a San Francisco federal court on Monday. He was arrested in Cyprus in May 2025 and extradited to the U.S. last week, according to the Justice Department.

The indictment, originally filed in 2021, accuses Aktulaev of deploying a variant of the TVRAT malware — also known as TVSPY or TeamSpy — through the messaging platform of a freelance employment tech company. Between June 2016 and November 2017, he allegedly spread the malware to roughly 80,000 of the site’s users.

Prosecutors say Aktulaev sent messages from 255 fake user accounts, each carrying malicious Microsoft Excel attachments. When victims opened those files, they were prompted to take actions that secretly downloaded the malware onto their devices.

The indictment remains sealed as of Wednesday, and the DOJ has not named the freelance company that was hit.

How the malware worked

TVRAT is a nasty piece of code that exploits a vulnerability in TeamViewer, a popular remote access tool. Once installed, it gives attackers full control over a victim’s device.

Aktulaev also used a second strain of malware called DarkVNC, which did the same thing but targeted a bug in VNC Viewer, another remote administration tool.

With that level of access, Aktulaev allegedly stole data and committed fraud. He kept command-and-control domains active after the initial infection, allowing him to return to compromised devices whenever he wanted.

Victims concentrated in California

About half of the victims were based in the U.S., with a heavy concentration in California. Prosecutors say Aktulaev maintained a document containing stolen e-commerce login credentials and personal information for hundreds of victims.

That document alone paints a picture of a long-running operation — not a one-off hack. The scale of it, 80,000 infected freelancers, makes it one of the more significant malware campaigns aimed at remote workers in recent memory.

Charges and potential sentence

Aktulaev faces multiple charges, including:

  • Conspiracy
  • Aggravated identity theft
  • Transmission of a program, information, code, and command to cause damage to a protected computer

If convicted on all counts, the maximum sentence is 20 years in federal prison.

He is currently in federal custody, with his next hearing scheduled for October 5.

Why this matters for freelancers

This case is a stark reminder that freelancers are prime targets for cybercriminals. They often work from personal devices, handle sensitive client data, and communicate through platforms that may not have enterprise-grade security.

The attack vector here — malicious Excel attachments sent through a legitimate messaging system — is still one of the most common ways malware spreads. A 2016 campaign like this one would have been cutting-edge then, but the techniques remain relevant today.

For anyone working remotely, the lesson is simple: be wary of unexpected attachments, even from people you think you know. And if a file asks you to enable macros or take other unusual steps, stop and think before clicking.

This case also highlights how international cybercrime prosecutions work. Aktulaev was arrested in Cyprus, extradited to the U.S., and is now facing justice in San Francisco. It’s a slow process, but it shows that law enforcement agencies are willing to chase suspects across borders.

The freelance platform targeted here hasn’t been named, but the impact on its users was clearly massive. For those 80,000 victims, the malware may have compromised everything from bank accounts to client contracts.

As the case moves forward, more details are likely to emerge. For now, Aktulaev sits in federal custody, awaiting his next court date. The outcome could set a precedent for how similar cross-border cybercrime cases are handled in the future.

Continue Reading

Infosecurity

FulcrumSec Drops 550GB of Manchester Airports Group Data — and It’s Almost All Out There

Published

on

FulcrumSec MAG breach

The Short Version: A Massive Dump, Almost Fully Public

A threat actor going by the name FulcrumSec says it has now published nearly all of the 550GB of data it stole from Manchester Airports Group (MAG), the UK’s largest airport operator. The group claims the leaked archive contains around 549GB of uncompressed customer information, which it describes as “pure PII.”

That’s a staggering volume of personal data. And if FulcrumSec’s claims check out, it dramatically expands what we know about an incident that MAG has said very little about since it first acknowledged a cyber incident back in late August.

How Did They Get In? Blame the Frontend JavaScript

FulcrumSec says the initial access wasn’t some sophisticated zero-day exploit. Instead, the group claims it found admin keys for Iterable, a customer engagement platform, sitting in the frontend JavaScript of all three MAG-owned airport websites: Manchester, Stansted, and East Midlands.

“These keys were not found on some obscure subdomain, as was the case with the credentials that led to our breaches of Arup Group and Novo Nordisk. All three of these were on the sites’ root domain,” the group’s leak note reads.

In other words, anyone who visited the sites could have hit “inspect element” and seen the keys. No subdomain enumeration. No URL crawling. Just plain sight.

What Exactly Was Stolen? A Lot More Than MAG Admitted

MAG’s initial disclosure was thin on details. FulcrumSec’s post paints a much broader picture of the exfiltration. The group claims to have taken:

  • Nearly 8.7 million customer profiles, including names, emails, mobile numbers, home towns, postcodes, and residential IP addresses.
  • Around 1.2 billion marketing events (sends, opens, clicks).
  • Almost 2.5 million purchase records — essentially every booking ever made for parking, Fast Track, and lounge services.
  • Over 461,000 SMS messages containing passenger booking dates, car park details, and vehicle registrations in plain text.
  • 108,000 unique vehicle registration plates.
  • Platform configuration data.

That’s a treasure trove for phishing campaigns. With residential IP addresses and mobile numbers in hand, attackers can craft highly convincing, targeted scams that are hard to spot.

The Physical Danger for Travellers

Perhaps the most alarming claim involves data on nearly 191,000 future bookings. FulcrumSec says this includes travel schedules, PII, and vehicle information that could allow criminals to target holidaymakers’ homes while they’re away.

The group even suggests that some of these individuals may be public figures, politicians, or military personnel, based on the email addresses tied to the bookings.

“Sadly MAG declined to pay the necessary fee to protect their passengers’ data, leaving us to remove the most sensitive parts … from the leak prior to publication,” FulcrumSec added.

That last line is worth pausing on. It implies the group edited the dump before release — which raises questions about what was left out, and why.

What MAG Has Said (and Not Said)

Manchester Airports Group has not issued an update since its original statement on August 27. Its initial post confirmed a cyber incident but offered little in the way of specifics. FulcrumSec’s claims remain unverified by independent researchers, and it’s possible the data is incomplete, repackaged, or partially fabricated.

That said, the group has a track record. It previously claimed breaches of Arup Group and Novo Nordisk, and its leak site is active. The MAG incident, if confirmed, would be one of the largest airport-related data breaches in UK history.

What Should Affected Passengers Do Now?

If you’ve used Manchester, Stansted, or East Midlands airports for parking, Fast Track, or lounge bookings, the risk is real. Here’s a practical checklist:

  1. Change your passwords — especially if you reuse them across sites. Use a password manager to generate unique ones.
  2. Enable two-factor authentication on your email and banking accounts immediately.
  3. Watch for phishing emails and SMS that reference your airport bookings. Be suspicious of any message asking you to click a link or confirm details.
  4. Monitor your credit reports for unusual activity over the coming months.
  5. Be cautious with travel plans — if you have an upcoming booking, consider whether you need to share additional personal details.

For more on how to protect yourself after a data breach, check out our guide on responding to a personal data leak. You might also want to read about how phishing attacks use stolen PII to understand the tactics criminals employ.

The Bottom Line

This is a developing story, and verification is pending. But the scale of the alleged leak — 550GB, millions of profiles, and a heap of sensitive travel data — is a stark reminder that exposed API keys can have catastrophic consequences.

MAG’s silence is deafening. Passengers deserve to know exactly what was taken, and what the group is doing about it. Until then, assume your data is out there and act accordingly.

Continue Reading

Infosecurity

Hackers Chain Two New SonicWall Zero-Days to Breach SMA1000 Gateways

Published

on

SonicWall zero-day vulnerabilities

SonicWall Sounds Alarm on Two Zero-Days Hitting SMA1000 Appliances

SonicWall has warned customers that attackers are actively chaining two newly disclosed zero-day vulnerabilities to break into SMA1000 secure access gateways. One of the flaws carries a perfect CVSS score of 10.0 — the highest severity rating possible.

The vendor’s security advisory, published September 1, says the bugs affect the SMA1000 series, specifically models 6210, 7210, and the 8200v virtual appliance. If you’re running version 12.4.3-03453 (platform-hotfix) or older, or 12.5.0-02835 (platform-hotfix) or older, you’re exposed.

These SonicWall SMA appliances are the gateways that let remote workers tunnel into corporate networks. They’re prime targets for state-sponsored groups and ransomware crews because they sit at the edge, guarding access to sensitive internal resources.

The Big One: A Pre-Auth SSRF with a Perfect CVSS Score

The more dangerous of the two is CVE-2026-83548, a pre-authentication server-side request forgery (SSRF) vulnerability lurking in the SMA1000 Appliance Work Place interface. SonicWall attributes it to an “unintended alternate access path.”

What does that mean in practice? A remote attacker with no credentials can exploit this flaw to reach sensitive functionality and pull off unauthorized operations. No login required. No user interaction. Just a clear path in.

The flaw’s CVSS score of 10.0 tells you everything about how seriously you should take it.

The Second Flaw: Post-Auth RCE in the Management Console

The second zero-day, CVE-2026-83549, is a post-authentication remote code execution (RCE) vulnerability in the SMA1000 Appliance Management Console. Its CVSS score sits at 7.8 — high, but not quite as dire.

SonicWall describes it as a “post-authentication improper neutralization of special elements used in an OS command.” In plain English: an authenticated attacker with administrator rights can, under specific conditions, execute arbitrary OS commands on the appliance. That’s a full system compromise waiting to happen.

What SonicWall Tells Customers to Do Right Now

SonicWall isn’t mincing words. Whether you run physical or virtual SMA1000 appliances, the vendor wants action — not just acknowledgment.

Here’s the remediation checklist from the advisory:

  • Upgrade immediately to the latest hotfix version for your appliance.
  • Contact SonicWall Technical Support for help hunting for indicators of compromise (IoCs).
  • If IoCs are found: re-image hardware or re-deploy virtual appliances, change every user and admin password, and reset all TOTP tokens.

That last step is heavy, but it’s necessary. If attackers have already established persistence, a simple patch won’t kick them out.

Why Edge Devices Keep Getting Hit

This isn’t SonicWall’s first rodeo with zero-days. The company previously probed attacks using zero-days in its own products, and the pattern is familiar across the industry.

Edge devices like SMA1000 are attractive precisely because they’re the front door to corporate networks. Remote access security depends on these gateways being bulletproof, yet they keep revealing cracks. In February 2025, Five Eyes intelligence agencies published guidance for edge device manufacturers, pushing for better baseline security. The message hasn’t fully sunk in.

For administrators, the takeaway is blunt: check your SMA1000 firmware version today. If you’re on an affected build, don’t wait for a maintenance window. Attackers certainly aren’t waiting.

And if you suspect compromise, incident response best practices suggest assuming the worst — re-image, rotate credentials, and reset multi-factor authentication tokens before you do anything else.

Continue Reading

Infosecurity

Nutex confirms patient and employee data stolen in August cyberattack

Published

on

Nutex data breach

Nutex confirms data theft in SEC filing

Houston-based healthcare operator Nutex has confirmed that hackers made off with patient and employee data during a cyberattack disclosed last week. In an 8-K filing with the Securities and Exchange Commission (SEC) on Monday, the company said it is being extorted by cybercriminals who broke into its servers and exfiltrated sensitive information.

The stolen data includes patient records, employee details, information from external providers, and confidential financial documents. Nutex said the attackers have threatened to post the information publicly if their demands are not met.

“The third party has threatened to post such information externally,” the company stated, adding that it is still investigating the full scope of the breach and its potential impact.

What we know about the Nutex cyberattack

Nutex initially disclosed the attack to the SEC on August 24, saying it had hired cybersecurity experts to respond. The company operates 27 hospital and outpatient facilities across 12 states and a physician network focused on primary care. It generated $427.2 million in revenue in the first half of 2026.

Monday’s filing also revealed that a class action lawsuit has been filed in Texas. The complaint was brought on behalf of individuals whose personally identifiable information or protected health information may have been accessed during the incident.

Nutex said it is “unable to predict the outcome of the litigation or estimate the potential impact of the incident on the Company’s business strategy, operations, financial condition, results of operations or the trading price of the Company’s common stock.”

The Gentlemen ransomware gang takes credit

The 8-K filing did not name a specific cybercrime group, but on Monday The Gentlemen ransomware gang added Nutex to its leak site, claiming responsibility for the attack.

The ransomware-as-a-service operation has been active since September 2025. Experts believe it was created by a disgruntled former affiliate of the Qilin ransomware group. The gang has launched at least 350 attacks since emerging and is thought to be based in Russia, as it prohibits attacks on Commonwealth of Independent States (CIS) countries and its forum posts are written in Russian.

The Gentlemen allows affiliates to conduct both ransomware attacks and data exfiltration-only incidents, taking just a 3% cut of ransoms from the latter. The group recently made headlines for shutting down the IT system of nonprofit medical system AnMed and taking over its Facebook page, forcing dozens of facilities to close for days.

Rising threat to healthcare

In the second quarter of 2026, The Gentlemen claimed 125 attacks on industrial organizations, according to the operational technology firm Dragos — the third most among ransomware groups. Two weeks ago, experts at Gambit Security reported seeing an affiliate using Claude Code during intrusions into at least six organizations.

Healthcare remains a prime target for ransomware gangs because of the sensitive nature of patient data and the operational chaos caused by system shutdowns. For hospitals, a breach can mean cancelled procedures, delayed care, and long-term reputational damage.

Nutex has not responded to requests for comment. The company said it is working with cybersecurity experts and law enforcement to address the incident.

For more on how ransomware groups operate, see our coverage of ransomware attack trends and healthcare cybersecurity best practices.

Continue Reading

Trending