A California federal grand jury has indicted a Russian national on charges tied to a phishing campaign that infected thousands of freelance workers with remote-access malware. The defendant, 40-year-old Searzhudin Tamirlanovich Aktulaev, was extradited to the United States after his arrest in May 2025 at Larnaca Airport in Cyprus. Court documents filed in June 2021 and unsealed this week allege that Aktulaev targeted users of an unnamed freelance employment technology company based in the Northern District of California.
According to the indictment, between June 2016 and November 2017, Aktulaev used 255 fake user accounts on the company's online messaging platform to send Microsoft Excel attachments to roughly 80,000 freelancers. Those attachments contained malicious macros that, when opened, downloaded malware onto the victims' systems. The campaign affected freelancers worldwide, with investigators finding that about half of all infected victims were located in the United States, many within the Northern District of California.
The malware deployed in the attacks included TVRAT, also known as TeamSPy or TVSPY, and DarkVNC. Both tools gave Aktulaev remote control over infected computers through legitimate remote administration software, with TVRAT operating via TeamViewer and DarkVNC using VNC Viewer. The Department of Justice said both malware strains sent stolen data from victim machines to command-and-control servers, where Aktulaev and his co-conspirators collected the information to commit fraud or other criminal activity.
The stolen data included e-commerce login credentials and personally identifiable information from the victims. The Justice Department also noted that the command-and-control domains were paid for using virtual currency, and that thousands of computers infected with TVRAT were calling back to a command-and-control domain hosted in the United States. Aktulaev is now in federal custody and is scheduled to appear before U.S. District Judge Donato on October 5.
In a separate but related development announced on Monday, the U.S. Justice Department said it is working with international law enforcement and private partners on a global action to dismantle the malware infrastructure of the Russian-linked Sality botnet. That effort was disclosed as part of a broader push against cyber threats originating from Russia. The freelance platform targeted in the Aktulaev case was not identified in the court documents, and no additional details were provided about the company or its response to the breach.
More cybersecurity news from TechManNews.






