A California federal grand jury has indicted a Russian national accused of running a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware.

The defendant, 40-year-old Searzhudin Tamirlanovich Aktulaev, was extradited to the United States after being arrested at Larnaca Airport in Cyprus in May 2025. Court documents originally filed in June 2021 and unsealed this week allege that he targeted users of an unnamed freelance employment technology company in Northern California through its online messaging platform.

Between June 2016 and November 2017, Aktulaev allegedly used 255 fake user accounts to send malicious Microsoft Excel attachments to around 80,000 freelancers. The attachments contained macros that downloaded malware from the internet onto victims’ computers.

The campaign involved TVRAT, also known as TeamSPy and TVSPY, along with DarkVNC. The malware gave Aktulaev remote access to infected computers through TeamViewer and VNC Viewer, allowing him to control compromised systems.

According to the U.S. Department of Justice, both malware families sent stolen information from victims’ computers to command-and-control servers. The collected data was allegedly used by Aktulaev and his co-conspirators for fraud and other criminal activity.

Investigators also found that the attackers used virtual currency to pay for their command-and-control domains, while thousands of computers infected with TVRAT connected back to a command-and-control server hosted in the United States.

The stolen information reportedly included e-commerce login credentials and personally identifiable information. Around half of the infected victims were located in the United States, with many based in Northern California.


Buy ExpressVPN with PayPal or Credit Card
READ
GS Retail Fined $9.3 Million After Data Leak Exposes 1.66 Million Customers

Aktulaev is currently in federal custody and is scheduled to appear before U.S. District Judge Donato on October 5.

Advertisement