Skip to content
Russian Man Extradited Over Malware Campaign Targeting Freelancers

Russian Man Extradited Over Malware Campaign Targeting Freelancers

Infosecurity-Magazine September 2, 2026

A Russian man has been extradited to the US over allegations that he helped distribute malware to approximately 80,000 users of a freelance employment platform between 2016 and 2017.

The US Department of Justice (DoJ) said Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025 and extradited on August 28, 2026. He made his initial federal court appearance in San Francisco on August 31 and was remanded to federal custody.

The DoJ said a federal grand jury had indicted Aktulaev on conspiracy, computer damage, unauthorized access and aggravated identity theft charges, among other offenses.

Freelance Platform Used to Distribute Malware

According to the indictment, Aktulaev and alleged co-conspirators used approximately 255 fake accounts on the messaging platform of a well-known freelance employment company in the Northern District of California to send malicious Microsoft Excel attachments between at least June 2016 and November 2017.

When opened, the attachments prompted recipients to run a macro, which then downloaded malware from the internet.

The campaign allegedly deployed two malware families. A variant of TVRAT, or TeamViewer Remote Access Trojan, also known as TVSPY or TeamSpy, exploited a vulnerability in TeamViewer to give remote control of infected computers, while DarkVNC had similar functionality through VNC Viewer.

Both remote access trojans sent stolen data to command-and-control (C2) servers, where prosecutors alleged it was collected and used for fraud and other criminal activity.

The indictment said the C2 domains were paid for with virtual currency, while thousands of computers infected with TVRAT were calling back to a C2 domain hosted in the US.

Thousands of Victims Linked to Command Infrastructure

Approximately half of the victims were in the US, many of them in the Northern District of California, according to prosecutors.

A database found on the C2 domain revealed thousands of victims. A shared document on an email account used in the alleged activity contained e-commerce login credentials and personally identifiable information (PII) for hundreds more.

If convicted, Aktulaev faces a maximum of 20 years for conspiracy to commit wire fraud, 10 years for transmitting code to damage protected computers and two years consecutive for each aggravated identity theft count, alongside fines of $250,000 or twice the gross gain.

The Federal Bureau of Investigation (FBI) led the investigation and the DoJ's Office of International Affairs secured the extradition. Aktulaev remains in federal custody and is scheduled to appear for a status conference on Oct. 5.

An indictment merely alleges that crimes have been committed, and Aktulaev is presumed innocent until proven guilty beyond a reasonable doubt.

FBI and French Police Shutter BreachForums Domain Again News 13 October 2025

FBI and French Police Shutter BreachForums Domain Again

International Law Enforcement Sinkhole GameOver Zeus and CryptoLocker Botnets News 2 June 2014

International Law Enforcement Sinkhole GameOver Zeus and CryptoLocker Botnets

Russian Espionage Group Static Tundra Targets Legacy Cisco Flaw News 21 August 2025

Russian Espionage Group Static Tundra Targets Legacy Cisco Flaw

FBI's Quest to Pierce Tor Could Open the Door to Foreign Surveillance News 22 September 2014

FBI's Quest to Pierce Tor Could Open the Door to Foreign Surveillance

Microsoft Warns of Increase in Business Email Compromise Attacks News 19 May 2023

Microsoft Warns of Increase in Business Email Compromise Attacks

What’s Hot on Infosecurity Magazine?

Cybersecurity Job Ads Requiring AI Skills Double

Healthcare Giant McKesson Investigates Data Breach Incident

Average Cyber Insurance Losses Increase Despite Fewer Claims

Manchester Airports Group Hit by Cyber Incident

Attackers Steal METR API Key and Burn $600,000 in AI Credits

65% of Enterprises Have Seen AI Agents Act Out of Scope

DDoS Attack Hits Norwegian Government Services

Manchester Airports Group Hit by Cyber Incident

Linux Foundation Introduces TRACE Standard for AI Runtime Evidence

Average Cyber Insurance Losses Increase Despite Fewer Claims

Agentic AI will Supercharge Cyber Threats. But Not in the Way You Think

Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign

Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser

How To Enhance Security Operations with AI-Powered Defenses

Behind the Curtain of Microsoft 365 Cybersecurity: Lessons from Overlooked Resilience Gaps

Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology

How to Manage Your Risks and Protect Your Financial Data

Dispelling the Myths of Defense-Grade Cybersecurity

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Researchers Claim First Fully Agentic Ransomware: JadePuffer

AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

How World Cup Password Trends Can Increase Active Directory Risk

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

Extracted Entities

APT Groups (1)

Attack Types (2)

Platforms (1)

Ransomware Groups (1)