← All stories
● Covered by 2 sources · 2 reportsMedium impact1 negative1 neutral

Russian National Charged in US for Malware Campaign Targeting 80,000 Freelancers

🔄 Updated 58m ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Searzhudin Tamirlanovich Aktulaev, 40, was extradited from Cyprus to the US.
  • He is charged with infecting 80,000 freelancers with TVRAT and DarkVNC malware.
  • The campaign ran from June 2016 to November 2017.
  • Malware was distributed via malicious Excel attachments on a freelance platform.
  • Aktulaev used 255 fake accounts to send the attachments.

Extradition and Charges

Searzhudin Tamirlanovich Aktulaev, a 40-year-old Russian national, has been extradited to the United States from Cyprus. He was arrested in Cyprus at Larnaca Airport in May 2025 and made his initial appearance in federal court in San Francisco on August 31, where he was remanded to federal custody.

A California federal grand jury indicted Aktulaev for his role in a phishing campaign. The indictment, filed on June 1, 2021, and unsealed this week, details the charges against him.

Malware Campaign Details

Between June 2016 and November 2017, Aktulaev allegedly exploited the online messaging platform of an unnamed freelance employment technology company based in the Northern District of California. He used 255 fake user accounts to send Microsoft Excel attachments containing malicious macros to approximately 80,000 freelancers.

These attachments downloaded malware from the internet onto the targets' systems. The malware included TVRAT (also known as TeamSPy and TVSPY) and DarkVNC, which provided Aktulaev with remote control over the infected systems via TeamViewer and VNC Viewer remote administration tools, respectively.

Impact and Data Theft

Both TVRAT and DarkVNC malware sent stolen data from victim computers to a command-and-control server. Thousands of computers infected with TVRAT were calling back to a command-and-control domain hosted in the U.S., with approximately half of the victims located in the country, many of them in the Northern District of California.

A shared document in the email account used in the scheme contained e-commerce login credentials and personally identifiable information (PII) for hundreds of victims.

Significance of the Case

This case highlights ongoing efforts by the U.S. Department of Justice to prosecute cybercriminals operating internationally. The extradition and subsequent charges demonstrate the reach of law enforcement in addressing cybercrime that crosses national borders and impacts a large number of individuals.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~24 min · 20 stories · Sep 01

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

A Russian national, Searzhudin Tamirlanovich Aktulaev, has been extradited from Cyprus to the U.S. and charged by the Department of Justice for orchestrating a malware campaign that infected thousands of computers between 2016 and 2017. The campaign used fake accounts on a freelance platform to distribute malware-laced Excel attachments, leading to remote control of infected systems and data theft, which matters as it highlights ongoing efforts to prosecute cybercriminals operating internationally.

A Russian national, Searzhudin Tamirlanovich Aktulaev, has been indicted in the US for a phishing campaign that infected 80,000 freelancers with TVRAT and DarkVNC malware. Aktulaev exploited an online messaging platform to send malicious Excel attachments, gaining remote control and stealing data from victims' systems.