A Russian national has been indicted on multiple charges related to a malware campaign that infected the devices of over 80,000 individuals. Searzhudin Tamirlanovich Aktulaev appeared in a federal court in San Francisco on Monday after being arrested in Cyprus in May 2025 and extradited to the U.S. last week. The indictment, which dates back to 2021, alleges that Aktulaev utilized a variant of the “TVRAT” malware—also known as “TVSPY” or “TeamSpy”—to spread malicious software through an online messaging platform of a freelance employment tech company between June 2016 and November 2017.
Aktulaev faces serious charges, including conspiracy, aggravated identity theft, and the transmission of a program designed to cause damage to a protected computer. If convicted, he could face a maximum sentence of 20 years in prison. During his initial court appearance, prosecutors revealed that the messages sent by Aktulaev originated from 255 fake user accounts and included malicious Microsoft Excel attachments. When opened, these attachments prompted users to take actions that resulted in the malware being downloaded onto their devices.
The indictment remains sealed, and the Justice Department has not disclosed the identity of the freelance company that was targeted. The TVRAT malware exploits vulnerabilities in the remote access tool TeamViewer, allowing attackers to take control of victims’ devices. Additionally, Aktulaev employed another strain of malware known as DarkVNC, which exploits a bug in the remote administration tool VNC Viewer.
Using the access gained through these malware infections, Aktulaev allegedly stole data from victims and committed fraud. Approximately half of the victims were located in the U.S., primarily in California. He maintained a document containing stolen e-commerce login credentials and personal information for hundreds of victims. Aktulaev is currently in federal custody, with his next hearing scheduled for October 5.
For more details, see the report by The Record.
Follow Cyber Warriors Middle East for further global cybersecurity developments.



