At a Glance
| Actor | Searzhudin Tamirlanovich Aktulaev |
| Activity Type | Malware distribution, wire fraud, identity theft |
| Targets | Users of a freelance employment platform |
| Scale | Approximately 80,000 targeted accounts; thousands infected |
| Status | In federal custody following extradition from Cyprus |
| Source | U.S. Department of Justice |
TL;DR
A federal grand jury indicted Russian national Searzhudin Tamirlanovich Aktulaev for targeting freelance workers with malware. Authorities extradited the suspect from Cyprus to California on August 28, 2026. He now faces federal charges for computer fraud and aggravated identity theft.
What Happened
Between June 2016 and November 2017, the suspect allegedly targeted workers on a popular freelancing platform. Specifically, he used roughly 255 fraudulent accounts to deliver phishing messages to victims. These messages contained malicious Microsoft Excel attachments with embedded macros. When victims opened the files, the macro downloaded trojans onto their workstations. The scheme deployed two distinct malware families known as TVRAT and DarkVNC. Furthermore, the indictment states that “TVRAT exploits a vulnerability in the popular remote administration tool TeamViewer to provide the subjects with remote control over the infected computer.” DarkVNC similarly abused VNC Viewer to gain remote control and steal user files.
Who Is Behind It
Federal prosecutors named 40-year-old Searzhudin Tamirlanovich Aktulaev as the lead suspect. Attribution confidence remains high because investigators tracked forensic records from command-and-control servers. Additionally, agents tied virtual currency payments directly to this infrastructure. The indictment also indicates that Aktulaev allegedly worked alongside unnamed co-conspirators.
Impact or Scale
The malware campaign targeted approximately 80,000 freelance contractors across the globe. Nearly half of these victims resided in the United States. Thousands of compromised systems communicated with servers hosted within American borders. Furthermore, agents discovered credentials and personal records belonging to hundreds of victims. This Russian national indicted by federal authorities allegedly used these stolen credentials for financial fraud.
What Comes Next and How to Stay Protected
Aktulaev made his initial court appearance in San Francisco and remains in federal custody. He will attend a status conference before U.S. District Judge Donato on October 5, 2026. Meanwhile, remote workers should never run macros from unsolicited documents. Security teams should also monitor remote management tools to prevent unauthorized access.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!