Skip to content
Bleeping Computer

US charges Russian for infecting 80,000 freelancers with malware


A California federal grand jury has indicted a Russian national for his role in a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware.

40-year-old Searzhudin Tamirlanovich Aktulaev was extradited to the United States after being arrested in Cyprus at Larnaca Airport in May 2025.

According to court documents filed in June 2021 and unsealed this week, Aktulaev allegedly infected thousands of users of an unnamed freelance employment technology company from the Northern District of California by exploiting the online messaging platform in phishing attacks.

Between June 2016 and November 2017, the defendant used 255 fake user accounts to send Microsoft Excel attachments with malicious macros to 80,000 freelancers, which downloaded malware from the Internet onto the targets’ systems.

Throughout these attacks, Aktulaev infected his victims’ devices with TVRAT malware (also known as TeamSPy and TVSPY) and DarkVNC, which gave him remote control over the infected system via TeamViewer and VNC Viewer remote administration tools, respectively.

“Both TVRAT and DarkVNC malware sent stolen data from a victim computer to a command-and-control server, from which the stolen data was collected and used by Aktulaev and his co-conspirators to commit fraud or other criminal activity,” the Department of Justice said.

“The command-and-control domains were paid for using virtual currency, and thousands of computers infected by the TVRAT malware were ‘calling back’ to a command-and-control domain hosted in the United States.”

He also stole the victims’ e-commerce login credentials and personally identifiable information. Investigators also found that half of all infected victims were in the United States, many in the Northern District of California.

Aktulaev is now in federal custody and is scheduled to appear before U.S. District Judge Donato on October 5.

On Monday, the U.S. Justice Department also announced that it’s working to dismantle the malware infrastructure of the Russian-linked Sality botnet in a joint global action with international law enforcement and private partners.

article image

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report



Source link