GKRootWire
Dev Tools Frustrated Developer Builds a Text Editor From ScratchDev Tools WebFPGA Brings FPGA Programming to the BrowserAI New Research Finds Hidden Symbolic Patterns Inside Neural NetworksGadgets iRobot's New Flagship Roomba Seals Itself to Your CarpetSecurity SonicWall Warns Attackers Are Chaining Two SMA1000 Zero-DaysGadgets Dell's New 14S Brings MacBook-Style Colors to Budget Student LaptopsDev Tools Frustrated Developer Builds a Text Editor From ScratchDev Tools WebFPGA Brings FPGA Programming to the BrowserAI New Research Finds Hidden Symbolic Patterns Inside Neural NetworksGadgets iRobot's New Flagship Roomba Seals Itself to Your CarpetSecurity SonicWall Warns Attackers Are Chaining Two SMA1000 Zero-DaysGadgets Dell's New 14S Brings MacBook-Style Colors to Budget Student Laptops
Security

US Charges Russian National in Phishing Scheme That Hit 80,000 Freelancers

A federal grand jury indictment alleges the suspect used fake job offers to plant remote-access malware on freelancers' computers worldwide.

A California federal grand jury has indicted a Russian national accused of running a large-scale phishing operation that targeted freelance workers around the globe. According to prosecutors, the scheme lured victims with fake job offers or client messages, tricking them into installing malicious attachments.

Once opened, the malware deployed two tools: TVRAT, which gave attackers remote control over infected machines, and DarkVNC, a hidden remote-desktop backdoor that let operators quietly watch and control victims' screens without their knowledge. Investigators say the campaign compromised roughly 80,000 machines belonging to freelancers, likely aiming to harvest payment credentials, client data, or account access for resale or further fraud.

The indictment is part of a broader US effort to prosecute foreign-based cybercriminals targeting American freelancers and gig workers, a group often lacking corporate IT protections.

Why it matters: Freelancers are attractive targets because they handle client payments and sensitive files without enterprise-grade security monitoring. This case is a reminder that job-offer phishing remains a highly effective malware delivery method, and gig workers should treat unsolicited attachments with the same suspicion as corporate employees do.

Sources: BleepingComputer