$ techbeacon▋
Phishing

Russian Expatriate Charged in Massive Freelance-Platform Phishing Scheme

Russian Expatriate Charged in Massive Freelance-Platform Phishing Scheme

A Russian citizen has been transferred to the United States to answer federal charges tied to a large‑scale phishing campaign that targeted users of an online freelance marketplace. Prosecutors say the scheme leveraged 255 fabricated accounts to circulate malicious Microsoft Excel files, compromising roughly 80,000 freelancers.

According to the indictment, the fake profiles were used to post job offers that appeared legitimate, prompting recipients to download attached spreadsheets. Once opened, the files executed hidden code designed to harvest login credentials and install additional malware on the victims' computers.

The operation exploited the trust inherent in gig‑economy platforms, where workers frequently exchange documents and files as part of project workflows. By mimicking genuine client communications, the attackers were able to bypass typical security cautions, leading many users to unwittingly install the payload.

Federal authorities highlighted the scale of the breach as a reminder of the evolving tactics cybercriminals employ against remote workers. While phishing attacks commonly rely on email, this case demonstrates how attackers can weaponize platform‑specific messaging systems to reach a concentrated audience.

Legal experts note that extradition of the suspect underscores the growing international cooperation in cybercrime investigations. The United States has increasingly pursued foreign nationals accused of digital offenses, seeking to deter transnational threat actors and reinforce the jurisdictional reach of its cyber‑security laws.

The case remains pending, with the defendant expected to appear before a federal court later this year. Meanwhile, the freelance platform involved has issued advisories urging users to verify the authenticity of file attachments and to employ multi‑factor authentication on their accounts. Cybersecurity professionals advise workers to treat any unsolicited spreadsheet with caution, especially those that request enabling macros or other executable content.

Source: GBHackers
Threat Desk — Threat desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related