Russian National Indicted for Malware Campaign Infecting 80,000 Freelancers, Faces 20 Years in Prison

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

A Russian national has been indicted on multiple charges related to a malware campaign that infected the devices of over 80,000 individuals. Searzhudin Tamirlanovich Aktulaev appeared in a federal court in San Francisco on Monday after being arrested in Cyprus in May 2025 and extradited to the U.S. last week. The indictment, which dates back to 2021, alleges that Aktulaev utilized a variant of the “TVRAT” malware—also known as “TVSPY” or “TeamSpy”—to spread malicious software through an online messaging platform of a freelance employment tech company between June 2016 and November 2017.

Aktulaev faces serious charges, including conspiracy, aggravated identity theft, and the transmission of a program designed to cause damage to a protected computer. If convicted, he could face a maximum sentence of 20 years in prison. During his initial court appearance, prosecutors revealed that the messages sent by Aktulaev originated from 255 fake user accounts and included malicious Microsoft Excel attachments. When opened, these attachments prompted users to take actions that resulted in the malware being downloaded onto their devices.

The indictment remains sealed, and the Justice Department has not disclosed the identity of the freelance company that was targeted. The TVRAT malware exploits vulnerabilities in the remote access tool TeamViewer, allowing attackers to take control of victims’ devices. Additionally, Aktulaev employed another strain of malware known as DarkVNC, which exploits a bug in the remote administration tool VNC Viewer.

Using the access gained through these malware infections, Aktulaev allegedly stole data from victims and committed fraud. Approximately half of the victims were located in the U.S., primarily in California. He maintained a document containing stolen e-commerce login credentials and personal information for hundreds of victims. Aktulaev is currently in federal custody, with his next hearing scheduled for October 5.

For more details, see the report by The Record.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

New MacSync Version Targets Crypto Enthusiasts with Advanced Infection Techniques

The emergence of the MacSync malware family marks a significant evolution in the landscape of cyber threats targeting macOS users, particularly those involved in...

Astrana Health Reports Data Breach Following Social Engineering Attack on Employees

Astrana Health has reported a data breach involving the theft of private and confidential information from its servers, following a social engineering attack that...

CloudSEK Addresses Escalating AI-Driven Cyber Risks in the Middle East

CloudSEK Tackles Rising AI-Driven Cyber Risks in the Middle East Cyber threats in the Middle East are escalating, with state-sponsored groups, ideologically motivated actors, and...

CWME_REVIEW_REQUIRED

CWME_REVIEW_REQUIRED Explore more technology and cybersecurity reporting from Cyber Warriors Middle East.