US charges Russian national in malware campaign that hit 80,000 freelancers

Suspect extradited from Cyprus faces federal indictment over TVRAT and DarkVNC infections

edit
By LineZotpaper
Published
Read Time2 min
A California federal grand jury has indicted a 40-year-old Russian national, Searzhudin Tamirlanovich Aktulaev, for a phishing campaign that infected up to 80,000 freelancers with remote-access malware between 2016 and 2017. Aktulaev was extradited to the United States after his arrest in Cyprus in May 2025, according to the Department of Justice.

Court documents filed in June 2021 and unsealed this week allege that Aktulaev targeted users of an unnamed freelance employment technology company in California's Northern District. Between June 2016 and November 2017, he is accused of using 255 fake user accounts to send Microsoft Excel attachments with malicious macros to 80,000 freelancers, which downloaded malware onto their systems.

Aktulaev allegedly infected victims with TVRAT (also known as TeamSPy and TVSPY) and DarkVNC, two remote-access trojans that gave him control over infected computers through TeamViewer and VNC Viewer. "Both TVRAT and DarkVNC malware sent stolen data from a victim computer to a command-and-control server, from which the stolen data was collected and used by Aktulaev and his co-conspirators to commit fraud or other criminal activity," the Department of Justice said.

The DOJ added that the command-and-control domains were paid for using virtual currency, and thousands of infected computers were "calling back" to a command-and-control domain hosted in the United States. Investigators also found that half of all infected victims were in the United States, many in the Northern District of California. Aktulaev also stole victims' e-commerce login credentials and personally identifiable information.

Aktulaev is now in federal custody and is scheduled to appear before U.S. District Judge Donato on October 5. The indictment follows a separate DOJ announcement on Monday of a joint global effort to dismantle the infrastructure of the Russian-linked Sality botnet.

§

Analysis

Why This Matters

  • The case shows how widely online work platforms can be exploited by cybercriminals, with tens of thousands of freelancers targeted through a single campaign.
  • The extradition from Cyprus underscores the growing international cooperation in prosecuting cybercrime suspects.
  • Stolen credentials and personally identifiable information from freelancers can feed further fraud, identity theft, and account takeovers long after the initial infection.

Background

Phishing campaigns using malicious macro-laden documents were a common initial-access technique during the mid-2010s, particularly against platforms where users expect files from prospective clients. Remote-access trojans like TVRAT and DarkVNC allow attackers to control systems covertly. The arrest and extradition of suspects abroad has become a more frequent feature of U.S. cybercrime enforcement, often following years of investigation and sealed charges.

Key Perspectives

Law enforcement (DOJ): The department frames the case as systematic fraud enabled by malware, with stolen data flowing to command-and-control servers and used by the defendant and co-conspirators for criminal purposes. Freelancers and platform users: The campaign exposed the risks of opening attachments from unknown contacts on freelance platforms, with victims potentially left exposed to credential theft and identity misuse. Critics and skeptics: The unnamed freelance platform's security practices and its response to the 2016-2017 campaign remain unclear, raising broader questions about how platforms detect and prevent such abuse without disclosing details.

What to Watch

  • Aktulaev's scheduled court appearance on October 5 before U.S. District Judge Donato.
  • Whether the DOJ names the affected platform or pursues additional co-conspirators.
  • Parallel investigations, such as the international push against the Sality botnet, that may signal a broader crackdown on Russian-linked infrastructure.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.