Um arquivo de proposta e cerca de 80 mil profissionais alcançados
The Record portal reported que o cidadão russo Searzhudin Tamirlanovich Aktulaev compareceu a um tribunal federal em São Francisco, depois de ter sido preso no Chipre, em maio de 2025, e extraditado para os Estados Unidos. Segundo a acusação, ele teria operado uma campanha de malware (programa malicioso criado para roubar dados ou assumir o controle de uma máquina) que alcançou cerca de 80 mil freelancers e prestadores de serviço em diferentes países. As acusações somam pena máxima de 20 anos de prisão, e o caso segue em andamento na Justiça americana.
For decision-makers, the most instructive point lies in the format of the bait. As described in the complaint, the files used in the campaign looked like the material a self-employed professional opens on any business day, such as a project briefing, a business proposal, or a technical test sent by a supposed client. Once executed, the code would look for credentials, access data, and financial information stored on the victim's equipment, quietly and with no ransom screen.
That gives rise to a question worth more than the case itself: how many files sent by people outside your org chart circulate through your operation in a single business day, and on which machines are they opened?
What the case means for companies that hire contractors
Practically every company with 5 to 5,000 employees works with outside people, whether a designer, translator, accountant, drafter, consultant, agency, or project-based developer. That partnership moves contracts, spreadsheets, artwork, code, and temporary access to shared folders, corporate email, and management systems. The point of concern lives in the equipment that takes part in your operation without taking part in your security policy, because the contractor's laptop rarely goes through the same controls as your internal fleet.
What you can put in place without slowing the operation down
The good news is that this risk has mature treatment, proportional to the size of each company. Files disguised as a proposal or briefing are exactly the type of threat that EDR (Endpoint Detection and Response) identifies by behavior, observing what the program does on the machine instead of relying on an already known signature. Alongside that, patch management keeps systems and applications up to date, closing the gaps that malicious code would use to escalate privileges.
Continuous proactive monitoring completes the set, flagging atypical logins, unusual download volumes, and uncommon activity in third-party accounts while the matter is still small. And tested backup with a disaster recovery plan secures the outcome, because if something gets through every layer, the operation comes back with minimal loss of data and time, also supporting contractual requirements regarding client information.
Does your company know exactly what each contractor can access?
If the answer takes more than a few minutes to put together, that is the first practical opportunity for gains. A simple inventory of third-party access, listing who logs in, into which system, with what permission level, and until when, usually reveals active accounts from completed projects, permissions that are far too broad for one-off tasks, and users shared by several people. Each of those findings is a quick, inexpensive fix with an immediate effect on risk.
From that map on, the rest becomes a natural sequence of managed IT, with MFA at every entry point, EDR on the machines that touch sensitive data, patch management on a defined cycle, continuous monitoring of external access, ongoing training for the team, and tested backup with a recovery plan. None of this requires restructuring the company, and it can all be rolled out in waves, starting with what protects revenue and reputation. Those who organize this set methodically gain something beyond security, which is the peace of mind of opening the operation to good partners without giving up control.
References
- The Record , Russian national facing 20 years over malware campaign
- Infosecurity Magazine , Pegasus zero-click exploit analysis
- Dark Reading , What we missed: did ShinyHunters breach ReliaQuest
Frequently asked questions
Why does a freelancer's device represent a risk to the hiring company?
External contractors usually use their own equipment, without the security controls applied to the hiring company's internal fleet. If that device is compromised, valid credentials can be collected and used to access the client's email, shared folders, and management systems. Because the login is legitimate, the access tends to look routine until someone observes the account's behavior.
Which controls reduce third-party access risk with the best cost-benefit?
The most effective combination starts with mandatory multifactor authentication at every entry point and application of the principle of least privilege, with temporary accounts that expire at the end of the project. Next come endpoint detection and response, patch management on a defined cycle, and continuous monitoring of external access. Tested backup with a recovery plan closes out the set and limits the impact of any incident.
Is traditional antivirus enough against malicious files disguised as a proposal?
Traditional antivirus relies on signatures of already cataloged threats, which leaves gaps when facing new or modified samples. Endpoint detection and response solutions analyze the behavior of the program while it runs, identifying suspicious actions even without knowing the file. That is why the recommendation is to combine behavioral detection, constant system updates, and strong identity controls.
If you want to see this access map clearly, Zamak conducts a Strategic IT Assessment, No Strings Attached.