Court documents filed in June 2021 and unsealed this week allege that Aktulaev targeted users of an unnamed freelance employment technology company in California's Northern District. Between June 2016 and November 2017, he is accused of using 255 fake user accounts to send Microsoft Excel attachments with malicious macros to 80,000 freelancers, which downloaded malware onto their systems.
Aktulaev allegedly infected victims with TVRAT (also known as TeamSPy and TVSPY) and DarkVNC, two remote-access trojans that gave him control over infected computers through TeamViewer and VNC Viewer. "Both TVRAT and DarkVNC malware sent stolen data from a victim computer to a command-and-control server, from which the stolen data was collected and used by Aktulaev and his co-conspirators to commit fraud or other criminal activity," the Department of Justice said.
The DOJ added that the command-and-control domains were paid for using virtual currency, and thousands of infected computers were "calling back" to a command-and-control domain hosted in the United States. Investigators also found that half of all infected victims were in the United States, many in the Northern District of California. Aktulaev also stole victims' e-commerce login credentials and personally identifiable information.
Aktulaev is now in federal custody and is scheduled to appear before U.S. District Judge Donato on October 5. The indictment follows a separate DOJ announcement on Monday of a joint global effort to dismantle the infrastructure of the Russian-linked Sality botnet.