A Russian national has been charged with infecting over 80,000 freelancers with malware in a sophisticated phishing campaign that highlights the ongoing threat of cybercrime. Searzhudin Tamirlanovich Aktulaev, 40, was extradited to the United States after being arrested in Cyprus and is now facing federal charges for his alleged role in the scheme.
According to court documents, Aktulaev used fake user accounts on an unnamed freelance employment technology company’s online messaging platform to send malicious Microsoft Excel attachments containing macros to freelancers. These emails, sent between 2016 and 2017, were designed to download malware from the internet onto the victims’ systems. The malware, known as TVRAT (TeamSPy) and DarkVNC, granted Aktulaev remote control over infected devices using TeamViewer and VNC Viewer remote administration tools.
The stolen data was then sent to a command-and-control server, where it was collected and used by Aktulaev and his co-conspirators for fraudulent activities. Investigators found that half of the infected victims were based in the United States, with many residing in the Northern District of California. The use of virtual currency to pay for command-and-control domains further highlights the sophistication of the operation.
The indictment against Aktulaev is a significant development in the ongoing battle against cybercrime. It demonstrates how attackers can exploit vulnerabilities in online platforms and compromise sensitive information. Moreover, it underscores the importance of cybersecurity awareness among freelancers, who often rely on these platforms for work opportunities. The fact that thousands of computers infected by TVRAT malware were “calling back” to a command-and-control domain hosted in the United States suggests that this is not an isolated incident.
The charges against Aktulaev also come as part of a broader effort to dismantle the malware infrastructure of the Russian-linked Sality botnet. This joint global action with international law enforcement and private partners aims to disrupt the operations of malicious actors who use such tools for nefarious purposes.
As cybersecurity threats continue to evolve, it’s essential for individuals and organizations to remain vigilant. Freelancers, in particular, should be cautious when interacting with online platforms and be aware of phishing attempts that can compromise their devices and sensitive information. While prevention scores may indicate a high level of protection, attackers can still breach defenses once they have valid credentials. It’s crucial to stay informed about emerging threats and take proactive measures to protect against cyber attacks.
In light of this case, it’s essential for freelancers to exercise extreme caution when receiving unsolicited emails or attachments from unknown sources. Verify the authenticity of messages and be wary of suspicious links or downloads. By being aware of these risks and taking necessary precautions, individuals can significantly reduce their vulnerability to cyber attacks.
Source: Bleeping Computer — 2026-09-02