Russian National Indicted for 2016 Malware Campaign Affecting 80,000 Users
A Russian national, **Searzhudin Tamirlanovich Aktulaev**, has been indicted on multiple charges related to a sophisticated malware campaign conducted between 2016 and 2017. The operation, which utilized variants of **TVRAT** and **DarkVNC** malware, compromised over 80,000 devices, with a significant portion of victims located in the U.S. Aktulaev was recently extradited from Cyprus and appeared in a San Francisco federal court.
A federal indictment has been unsealed against **Searzhudin Tamirlanovich Aktulaev**, a Russian national accused of orchestrating a widespread malware campaign that infected the devices of more than 80,000 individuals. Aktulaev, arrested in Cyprus in May 2025 and subsequently extradited, made his initial appearance in a San Francisco federal court this week.
### The Anatomy of the Attack
Prosecutors detail that the campaign, active from June 2016 to November 2017, leveraged the online messaging platform of a freelance employment technology company. Aktulaev allegedly used 255 fake user accounts to disseminate malicious **Microsoft Excel** attachments.
Upon opening these attachments, users were prompted to take actions that facilitated the download and installation of malware onto their devices.
### Malware Variants and Exploitation
The indictment specifically mentions Aktulaev's use of a variant of the **TVRAT** malware, also known as **TVSPY** or **TeamSpy**. This malware exploits vulnerabilities in the remote access tool **TeamViewer**, allowing attackers to gain unauthorized control over a victim's device.
Additionally, Aktulaev employed another strain of malware known as **DarkVNC**, which similarly exploited a bug in the remote administration tool **VNC Viewer** to achieve device takeover.
### Data Theft and Fraud
With unauthorized access to compromised devices, Aktulaev systematically stole data from victims and engaged in fraudulent activities. He maintained persistent access to these devices through various command-and-control (C2) domains.
Approximately half of the victims were based in the U.S., with a concentration in California. Investigators discovered a document in Aktulaev's possession containing stolen e-commerce login credentials and personal information belonging to hundreds of victims.
### Charges and Legal Proceedings
Aktulaev faces serious charges, including conspiracy, aggravated identity theft, and transmission of a program, information, code, and command to cause damage to a protected computer. If convicted, these charges carry a maximum sentence of 20 years in prison.
Currently held in federal custody, Aktulaev's next court hearing is scheduled for October 5.