Russian National Indicted for Large-Scale Freelancer Phishing Campaign
A California federal grand jury has indicted **Searzhudin Tamirlanovich Aktulaev**, a Russian national, for orchestrating a sophisticated phishing campaign. The operation infected thousands of freelancers with **TVRAT** and **DarkVNC** malware, enabling remote control and data theft. Aktulaev was recently extradited to the U.S. after his arrest in Cyprus.

A California federal grand jury has indicted Russian national **Searzhudin Tamirlanovich Aktulaev** for his alleged role in a widespread phishing campaign. The operation led to the infection of thousands of freelancers with **TVRAT** and **DarkVNC** malware.
**Aktulaev**, 40, was extradited to the United States following his arrest at Larnaca Airport in Cyprus in May 2025.
### Phishing Exploits Target Freelancers
According to court documents, which were filed in June 2021 and unsealed this week, **Aktulaev** is accused of exploiting the online messaging platform of an unnamed freelance employment technology company. Between June 2016 and November 2017, he allegedly used 255 fake user accounts to dispatch malicious Microsoft Excel attachments containing macros to approximately 80,000 freelancers.
These malicious attachments were designed to download malware onto the targets' systems.
### Malware Deployed: TVRAT and DarkVNC
The attacks infected victims' devices with **TVRAT** malware (also known as **TeamSPy** and **TVSPY**) and **DarkVNC**. These tools provided **Aktulaev** with remote control over infected systems via **TeamViewer** and **VNC Viewer** remote administration tools, respectively.
"Both **TVRAT** and **DarkVNC** malware sent stolen data from a victim computer to a command-and-control server, from which the stolen data was collected and used by **Aktulaev** and his co-conspirators to commit fraud or other criminal activity," stated the **Department of Justice**.
Investigators noted that the command-and-control domains were financed using virtual currency, and thousands of infected computers were observed "calling back" to a U.S.-hosted command-and-control domain.
### Data Theft and Ongoing Proceedings
Beyond remote control, the campaign also aimed at stealing victims' e-commerce login credentials and personally identifiable information. Investigations revealed that half of the infected victims were located in the United States, with a significant number in the Northern District of California.
**Aktulaev** is currently in federal custody and is scheduled to appear before U.S. District Judge Donato on October 5.
This indictment follows a recent announcement by the U.S. Justice Department regarding its efforts to dismantle the malware infrastructure of the Russian-linked **Sality botnet**, in collaboration with international law enforcement and private partners.