US Indicts Russian National Over Malware Campaign Targeting 80,000 Freelancers
A California federal grand jury has indicted a Russian national for orchestrating a phishing campaign that infected approximately 80,000 freelancers with TVRAT and DarkVNC malware. The Russian malware indictment marks a significant enforcement action against cybercriminals targeting the gig economy workforce.
Searzhudin Tamirlanovich Aktulaev, 40, was arrested at Larnaca Airport in Cyprus in May 2025 and subsequently extradited to the United States. Court documents filed in June 2021 and unsealed this week detail how the defendant exploited an online messaging platform belonging to an unnamed freelance employment technology company based in the Northern District of California.

How the Russian malware indictment unfolded
Between June 2016 and November 2017, Aktulaev operated 255 fake user accounts to distribute his attack. He sent Microsoft Excel attachments containing malicious macros to 80,000 freelancers. When victims opened these files, the macros automatically downloaded malware onto their systems without additional user interaction.
The Russian malware indictment reveals that Aktulaev deployed two distinct tools to compromise his targets. TVRAT (also known as TeamSPy and TVSPY) and DarkVNC both granted him remote control over infected machines through legitimate remote administration software—TeamViewer and VNC Viewer respectively. This approach allowed him to operate undetected within victim systems.
Data theft and criminal infrastructure
According to the Department of Justice, both malware variants sent stolen data to command-and-control servers operated by Aktulaev and his co-conspirators. The stolen information was then used to commit fraud and other criminal activity. Investigators discovered that Aktulaev stole e-commerce login credentials and personally identifiable information from his victims, with roughly half of all infected machines located in the United States.
The infrastructure supporting this operation was deliberately obscured. Command-and-control domains were paid for using virtual currency, and thousands of infected computers “called back” to a command-and-control domain hosted within the United States itself. This follows a pattern seen in related developments, such as CISA Warns of Critical Gitea Vulnerability Exploited in Code Injection Attacks which highlighted how attackers exploit legitimate infrastructure for malicious purposes.
Aktulaev remains in federal custody and is scheduled to appear before U.S. District Judge Donato on October 5. The case reflects broader law enforcement efforts against cybercriminals; as covered earlier, NovaCookies Phishing Toolkit Exploits DocuSign to Hijack Microsoft 365 Sessions demonstrated how attackers continue to evolve their targeting methods against enterprise users.
المصدر: BleepingComputer