A Russian national, Searzhudin Tamirlanovich Aktulaev, has been indicted by a US federal grand jury for orchestrating a massive phishing campaign targeting 80,000 freelancers.

  • Defendant Searzhudin Tamirlanovich Aktulaev faces charges for a massive phishing campaign.
  • 80,000 freelancers were targeted using malicious Microsoft Excel attachments.
  • Malware used included TVRAT (TeamSPY) and DarkVNC for remote control.
  • The operation aimed to steal e-commerce credentials and personally identifiable information.

In a significant crackdown on international cybercrime, a California federal grand jury has indicted Searzhudin Tamirlanovich Aktulaev, a 40-year-old Russian national. Aktulaev is accused of spearheading a sophisticated phishing campaign that compromised the devices of approximately 80,000 freelancers through the deployment of TVRAT and DarkVNC malware.

The indictment, which was unsealed this week, details a campaign that took place between June 2016 and November 2017. According to court documents, Aktulaev utilized 255 fraudulent user accounts on an unnamed freelance employment technology platform. By sending Microsoft Excel attachments embedded with malicious macros, he successfully tricked thousands of users into downloading malware directly onto their systems.

The Mechanics of the Attack

The malware deployed in these attacks was highly invasive. TVRAT (also known as TeamSPY) and DarkVNC allowed the attackers to gain remote administrative control over the infected computers. By leveraging legitimate remote administration tools like TeamViewer and VNC Viewer, the perpetrators could operate the victims' machines as if they were sitting in front of them.

The stolen data was sent to command-and-control servers, enabling the conspirators to commit widespread fraud and identity theft.

BozokMedia analysis shows that the primary objective was the theft of high-value data, including e-commerce login credentials and sensitive personally identifiable information (PII). Investigators noted that half of the victims were located within the United States, particularly in the Northern District of California.

Historical Context: The Global Fight Against Botnets

This indictment follows a broader trend of international law enforcement agencies working to dismantle Russian-linked cyber infrastructures. Most recently, the U.S. Department of Justice announced a joint global action to dismantle the Sality botnet, highlighting the persistent threat posed by state-linked or state-adjacent cybercriminal groups.

Why Traditional Defenses Often Fail

A critical finding in recent cybersecurity intelligence is the vulnerability of systems once legitimate credentials are stolen. The Blue Report 2026 highlights a terrifying reality: once attackers bypass initial defenses using valid credentials, the effective prevention rate drops to just 37%.

Malware NamePrimary FunctionControl Method
TVRAT (TeamSPY)Data Theft & Remote AccessTeamViewer
DarkVNCRemote Desktop ControlVNC Viewer
Did You Know?: Cybercriminals often use 'Command-and-Control' (C2) domains, which are sometimes paid for using cryptocurrency to remain anonymous.

Frequently Asked Questions

Question 1: How was the suspect apprehended?
Aktulaev was arrested at Larnaca Airport in Cyprus in May 2025 and subsequently extradited to the United States.

Question 2: What makes this phishing attack so effective?
The use of malicious macros in common file types like Excel allows the malware to bypass casual scrutiny and execute automatically upon opening.