Skip to main content
Emerging ThreatsMalware & Ransomware

Russian Man Extradited for Malware Campaign Targeting Freelancers

Federal courthouse interior with defendant and blurred DOJ seal in background.

Approximately 80,000 users of a freelance employment platform were targeted in a malware campaign between 2016 and 2017, federal prosecutors say — a scale that underpins the charges brought after an international arrest and extradition.

Extradition, charges, and immediate court dates for Searzhudin Tamirlanovich Aktulaev

The Department of Justice announced that Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025 and extradited to the United States on August 28, 2026. He made his initial federal court appearance in San Francisco on August 31 and was remanded to federal custody. Aktulaev is indicted by a federal grand jury on a range of counts including conspiracy, computer damage, unauthorized access and aggravated identity theft, among other offenses. He is scheduled to appear for a status conference on October 5.

The indictment notes potential penalties if convicted: a maximum of 20 years for conspiracy to commit wire fraud, 10 years for transmitting code to damage protected computers, and two years consecutive for each aggravated identity theft count, along with fines of $250,000 or twice the gross gain. As the DOJ stated, an indictment merely alleges that crimes have been committed and Aktulaev is presumed innocent until proven guilty beyond a reasonable doubt.

Alleged distribution method: fake accounts and malicious Excel attachments on a freelance platform

Prosecutors say Aktulaev and alleged co-conspirators employed roughly 255 fake accounts on the messaging platform of a "well-known freelance employment company" within the Northern District of California. Between at least June 2016 and November 2017, those accounts sent malicious Microsoft Excel attachments to users of the platform. When opened, the attachments prompted recipients to run a macro, and the macro then downloaded malware from the internet.

TVRAT (TeamSpy) and DarkVNC: the remote access trojans named in the indictment

The indictment identifies two malware families deployed in the campaign. One is described as a variant of TVRAT — also called the TeamViewer Remote Access Trojan, TVSPY, or TeamSpy — which prosecutors say exploited a vulnerability in TeamViewer to give remote control of infected machines. The other, DarkVNC, is said to provide similar remote-control functionality through VNC Viewer. Both remote access trojans are accused of sending stolen data to command-and-control (C2) servers.

Prosecutors allege that the data collected at those C2 servers was used for fraud and other criminal activity.

Command-and-control infrastructure, victim records, and payment mechanisms

The indictment links the alleged campaign to an extensive command-and-control infrastructure. Prosecutors say thousands of computers infected with the TVRAT variant were calling back to a C2 domain hosted in the United States. A database found on that C2 domain reportedly revealed thousands of victims, and a shared document on an email account used in the alleged activity contained e-commerce login credentials and personally identifiable information for hundreds more.

Prosecutors also allege that the C2 domains were paid for with virtual currency.

What this means for technologists, affected freelancers, and law enforcement

  • Technologists and security teams: The indictment highlights specific indicators — malicious Microsoft Excel attachments that request macros and the named malware families TVRAT/TeamSpy and DarkVNC — that appear central to the campaign. The case centers on remote-access capabilities and C2 infrastructure, which prosecutors say was used to collect data that facilitated fraud.
  • Affected freelancers and platform users: Prosecutors say approximately 80,000 users were targeted and that roughly half of the victims were in the United States, with many located in the Northern District of California. The records allegedly found on C2 infrastructure and in a shared document reportedly included e-commerce credentials and PII for hundreds of people.
  • Law enforcement and international cooperation: The Federal Bureau of Investigation led the investigation and the DOJ's Office of International Affairs secured the extradition, underscoring the cross-border effort behind bringing the case to U.S. courts. Aktulaev remains in federal custody as the case proceeds to the scheduled status conference on October 5.

The indictment paints a picture of a multi-year, large-scale campaign that combined social-engineered messages on a freelance platform with Excel macros, remote-access trojans and centrally operated C2 infrastructure. With extradition completed and evidence described in court filings — including a C2-hosted database and shared documents containing credentials and PII — the next clear marker in the public record is the October 5 status conference and whatever procedural steps follow in the Northern District of California.

Original story