Skip to main content
Emerging ThreatsMalware & Ransomware

US Indicts Russian for Infecting 80,000 Freelancers with Malware

A cluttered freelance workspace with a laptop and crumpled paper on a desk.

Between June 2016 and November 2017, 255 fake user accounts were used to send Microsoft Excel attachments with malicious macros to 80,000 freelancers, according to court records now unsealed by the U.S. Justice Department.

The phishing campaign against freelancers

Federal prosecutors say the campaign targeted users of an unnamed freelance employment technology company by exploiting the platform’s online messaging feature to deliver malicious attachments. Court documents filed in June 2021 and unsealed this week describe a sustained operation in which those 255 fake accounts distributed Excel files containing macros that, when opened, downloaded additional software from the Internet onto victims’ systems.

Investigators determined roughly half of the infected victims were located in the United States, with many in the Northern District of California. The indictment was returned by a California federal grand jury.

TVRAT (TeamSPy/TVSPY) and DarkVNC: remote access and data exfiltration

Prosecutors say the attacker deployed two families of malware — TVRAT (also tracked as TeamSPy and TVSPY) and DarkVNC. Those malware strains gave remote control of compromised systems via TeamViewer and VNC Viewer remote administration tools, prosecutors allege.

The Department of Justice described how the malware operated: “Both TVRAT and DarkVNC malware sent stolen data from a victim computer to a command-and-control server, from which the stolen data was collected and used by Aktulaev and his co-conspirators to commit fraud or other criminal activity.” Investigators also found that the intrusions yielded stolen e-commerce login credentials and personally identifiable information.

Command-and-control infrastructure and payments

Court material quotes prosecutors saying the command-and-control domains supporting the malware were paid for using virtual currency. The records further state that thousands of computers infected by the TVRAT malware were “calling back” to a command-and-control domain hosted in the United States.

Separately, the Justice Department announced it is working to dismantle the infrastructure of the Russian-linked Sality botnet in a joint global action with international law enforcement and private partners — a parallel effort the department said was part of wider work against malware ecosystems.

Extradition, indictment, and the next court date

The defendant named in the indictment is 40-year-old Searzhudin Tamirlanovich Aktulaev. According to prosecutors, Aktulaev was arrested in Cyprus at Larnaca Airport in May 2025 and subsequently extradited to the United States. He is now in federal custody and is scheduled to appear before U.S. District Judge Donato on October 5.

What this means for technologists, affected freelancers, and U.S. prosecutors

  • Technologists and security teams: The unsealed documents underline how commodity malware combined with social-engineered delivery (malicious Office macros) can yield large-scale access and data exfiltration. The article also notes that “overall prevention scores can hide what happens after initial access,” and cites the Blue Report 2026, which measures defenses technique by technique across 338 million simulations run in customer production environments.
  • Affected freelancers and procurement leads for online platforms: The scale of the alleged campaign — 80,000 recipients and thousands of systems calling back to C2 infrastructure — reinforces the risk of credential theft and PII loss when platform messaging is used to deliver attachments. The indictment ties stolen credentials to subsequent fraud or other criminal activity.
  • U.S. prosecutors and international law enforcement: The case demonstrates cross-border cooperation — an arrest in Cyprus followed by extradition and a U.S. grand jury indictment — and aligns with the Justice Department’s announced, coordinated work to disrupt other botnet infrastructures such as the Russian-linked Sality network.

The facts in the unsealed indictment are blunt: a years‑long phishing operation, tens of thousands of targeted messages, and malware that turned freelancers’ devices into remote-access footholds and data-exfiltration points. The immediate next steps are procedural — an October 5 appearance before U.S. District Judge Donato and ongoing efforts by the Justice Department to dismantle related malicious infrastructure — but the record already testifies to the scale and reach of attacks that begin with a seemingly ordinary Excel attachment.

Original story