Russian National Accused of Infecting About 80,000 Freelancers With Malware

03.09.2026 2 minutes Author: Newsman

A federal grand jury in California indicted a Russian national suspected of participating in a malware campaign that targeted more than 80,000 freelancers.

Forty-year-old Searzhudin Tamirlanovich Aktulaev was extradited to the United States after being arrested in Cyprus in May 2025.

According to the indictment, filed on June 1, 2021, and unsealed on Tuesday, Aktulaev and his co-conspirators allegedly attempted to distribute malware to approximately 80,000 freelancers using the platform of a well-known employment technology company based in the Northern District of California.

Aktulaev created messages that were sent from 255 fake user accounts. They contained malicious Microsoft Excel attachments. After opening the files, users were prompted to enable a macro that downloaded malware from the internet.

According to the US Department of Justice, Aktulaev used two types of malware: TVRAT, a remote access Trojan associated with TeamViewer, and DarkVNC.

TVRAT exploited a vulnerability in TeamViewer that allowed Aktulaev to remotely control infected computers. DarkVNC offered similar capabilities but operated through another remote administration tool called VNC Viewer.

“Both TVRAT and DarkVNC malware sent stolen data from a victim computer to a command-and-control server, from which the stolen data was collected and used by Aktulaev and his co-conspirators to commit fraud or other criminal activity,” the US Department of Justice said in a press release.

The command-and-control domains were paid for using virtual currency. At least one of them was hosted in the United States.

Law enforcement officers also discovered a document in an email account used for criminal activity. It contained login credentials for e-commerce websites and personally identifiable information belonging to hundreds of victims.

Aktulaev is currently in federal custody. His next court hearing is scheduled for October 5, 2026. He faces charges of conspiracy to commit wire fraud, distributing malware to damage protected computers, unauthorized access, and aggravated identity theft.

If convicted, Aktulaev could face a combined maximum sentence of more than 35 years in prison. He may also be ordered to pay fines totaling up to $1 million or twice the gross proceeds obtained from the offenses, whichever amount is greater.

Subscribe
Notify of
0 Коментарі
Oldest
Newest Most Voted
Found an error?
If you find an error, take a screenshot and send it to the bot.