A California federal grand jury has indicted a Russian national for his role in a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware.
40-year-old Searzhudin Tamirlanovich Aktulaev was extradited to the United States after being arrested in Cyprus at Larnaca Airport in May 2025.
According to court documents filed in June 2021 and unsealed this week, Aktulaev allegedly infected thousands of users of an unnamed freelance employment technology company from the Northern District of California by exploiting the online messaging platform in phishing attacks.
Between June 2016 and November 2017, the defendant used 255 fake user accounts to send Microsoft Excel attachments with malicious macros to 80,000 freelancers, which downloaded malware from the Internet onto the targets' systems.
Throughout these attacks, Aktulaev infected his victims' devices with TVRAT malware (also known as TeamSPy and TVSPY) and DarkVNC, which gave him remote control over the infected system via TeamViewer and VNC Viewer remote administration tools, respectively.






