Russian National Indicted for Malware Campaign Infecting 80,000 Freelancers, Faces 20 Years in Prison

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

A Russian national has been indicted on multiple charges related to a malware campaign that infected the devices of over 80,000 individuals. Searzhudin Tamirlanovich Aktulaev appeared in a federal court in San Francisco on Monday after being arrested in Cyprus in May 2025 and extradited to the U.S. last week. The indictment, which dates back to 2021, alleges that Aktulaev utilized a variant of the “TVRAT” malware—also known as “TVSPY” or “TeamSpy”—to spread malicious software through an online messaging platform of a freelance employment tech company between June 2016 and November 2017.

Aktulaev faces serious charges, including conspiracy, aggravated identity theft, and the transmission of a program designed to cause damage to a protected computer. If convicted, he could face a maximum sentence of 20 years in prison. During his initial court appearance, prosecutors revealed that the messages sent by Aktulaev originated from 255 fake user accounts and included malicious Microsoft Excel attachments. When opened, these attachments prompted users to take actions that resulted in the malware being downloaded onto their devices.

The indictment remains sealed, and the Justice Department has not disclosed the identity of the freelance company that was targeted. The TVRAT malware exploits vulnerabilities in the remote access tool TeamViewer, allowing attackers to take control of victims’ devices. Additionally, Aktulaev employed another strain of malware known as DarkVNC, which exploits a bug in the remote administration tool VNC Viewer.

Using the access gained through these malware infections, Aktulaev allegedly stole data from victims and committed fraud. Approximately half of the victims were located in the U.S., primarily in California. He maintained a document containing stolen e-commerce login credentials and personal information for hundreds of victims. Aktulaev is currently in federal custody, with his next hearing scheduled for October 5.

For more details, see the report by The Record.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

GISEC Global 2026 to Host Cyber First Summit in Dubai, Addressing AI and Cybersecurity Challenges

The GISEC Global 2026 conference is set to take place from September 16 to 18 at the Dubai Exhibition Centre, Expo City Dubai, under...

Mirage Kitten Unveils NodeRabbit and PollCat, Its First Node.js and JavaScript Malware Families

Recent investigations into the activities of the cyber espionage group known as Mirage Kitten have revealed the emergence of two new malware families: NodeRabbit...

AI-Driven Ransomware Attack Utilizes Frontier AI to Breach Enterprise Network in Under 10 Hours

Unit 42 has reported a significant incident involving a ransomware attack where a human attacker utilized frontier AI to autonomously breach an enterprise network....

OpenAI to Release Astra, Its First AI Model with Critical Cybersecurity Capabilities

OpenAI announced Tuesday that its forthcoming AI model, Astra, is its first to reach the company’s threshold for what it calls “critical” cyber capabilities....