A 40-year-old Russian national has been extradited to the United States to face charges over an alleged malware campaign that targeted around 80,000 users of a freelance employment platform. The man, Searzhudin Tamirlanovich Aktulaev, was arrested in Cyprus in May 2025 and was extradited to the US on August 28, 2026. He appeared in federal court in San Francisco on August 31 and was placed in federal custody. The US Department of Justice said a federal grand jury has indicted him on several charges, including conspiracy, causing damage to protected computers, unauthorized computer access and aggravated identity theft.

According to the indictment, Aktulaev and his alleged co-conspirators used about 255 fake accounts on the messaging system of a well-known freelance employment technology company based in Northern California. The alleged campaign operated between at least June 2016 and November 2017 and used the platform’s own messaging system to reach freelancers. The attackers sent Microsoft Excel files containing malicious macros as attachments to approximately 80,000 users. When victims opened the files and followed the prompts to run the macros, the malicious code downloaded malware from the internet onto their computers.

The indictment names two types of malware allegedly used in the campaign, known as TVRAT and DarkVNC. TVRAT, also referred to as TVSPY or TeamSpy, allegedly abused a vulnerability in TeamViewer to give the attackers remote control of infected computers. DarkVNC worked in a similar way but used the VNC Viewer remote administration tool instead. Both forms of malware allegedly allowed stolen information to be sent from infected computers to attacker-controlled command-and-control servers. Prosecutors say the stolen information was then collected and used for fraud or other criminal activity.

Investigators also found evidence showing the scale of the alleged operation. The command-and-control domains were reportedly paid for using virtual currency, while thousands of computers infected with TVRAT were connecting back to a command-and-control domain hosted in the United States. The indictment says approximately half of the victims were located in the US, with many in Northern California. Investigators also found a database containing information about thousands of victims, along with a shared document containing e-commerce login credentials and personally identifiable information belonging to hundreds of people.

The case is now being handled by the National Security, Cyber, and Special Prosecutions Section, following an investigation by the Federal Bureau of Investigation. The Justice Department’s Office of International Affairs secured Aktulaev’s extradition from Cyprus on August 28, 2026, allowing the US prosecution to move forward. Aktulaev remains in federal custody and is scheduled to appear before US District Judge Donato for a status conference on October 5, 2026. The case highlights how attackers can misuse trusted communication systems and ordinary-looking office documents to reach large numbers of people.

However, it is important to note that the allegations have not yet been proven in court. The indictment only sets out the crimes prosecutors allege were committed, and Aktulaev is presumed innocent unless and until he is proven guilty beyond a reasonable doubt. If convicted, he could face significant prison sentences and financial penalties under the charges listed in the indictment, including a maximum of 20 years for the conspiracy charge and additional penalties for other alleged offenses. His next scheduled court appearance is October 5, 2026, as the US case continues.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news