A Russian National Indicted for Infecting 80,000 Freelancers with Malware in Massive Phishing Campaign
In a major crackdown on cybercrime, the US Department of Justice has indicted a 40-year-old Russian national for his role in a massive phishing campaign that infected over 80,000 freelancers with malware. Searzhudin Tamirlanovich Aktulaev, who was extradited to the United States after being arrested in Cyprus last year, allegedly used fake user accounts on an unnamed freelance employment technology company’s online messaging platform to send malicious Excel attachments to his victims.
Between June 2016 and November 2017, Aktulaev sent these fake attachments to tens of thousands of users, which downloaded malware from the internet onto their systems. The malware, known as TVRAT (also referred to as TeamSPy and TVSPY), gave him remote control over the infected systems via TeamViewer and VNC Viewer remote administration tools. Additionally, DarkVNC malware allowed Aktulaev to steal sensitive information, including e-commerce login credentials and personally identifiable data.
The phishing campaign was particularly sophisticated, with the defendant using virtual currency to pay for command-and-control domains hosted in the United States. This enabled him to collect stolen data from his victims’ computers and use it for fraudulent activities. Investigators found that half of all infected victims were located in the United States, many in the Northern District of California.
The indictment highlights the severity of cybercrime threats facing individuals and businesses today. The use of malware and phishing attacks has become increasingly common, with attackers often targeting vulnerable groups such as freelancers who may not have robust security measures in place. By exploiting online platforms and using sophisticated techniques to evade detection, cybercriminals can cause significant financial losses and damage reputations.
The indictment also comes as the US Department of Justice announced its efforts to dismantle the malware infrastructure of the Russian-linked Sality botnet in a joint global action with international law enforcement and private partners. This operation demonstrates the growing cooperation between governments and private sector organizations to combat cybercrime and disrupt malicious networks.
As this case demonstrates, protecting oneself from phishing attacks requires constant vigilance and awareness. It’s essential for individuals and businesses to implement robust security measures, including regular software updates, strong passwords, and multi-factor authentication. By staying informed about the latest threats and taking proactive steps to secure their systems, people can reduce their risk of falling victim to malware infections and other cybercrime schemes.
In conclusion, the indictment of Searzhudin Tamirlanovich Aktulaev serves as a warning to cybercriminals that their activities will not go unchecked. As law enforcement agencies and private sector organizations continue to collaborate on combating cybercrime, it’s crucial for individuals and businesses to stay informed and take proactive steps to protect themselves from malware infections and other threats.
Source: Bleeping Computer — 2026-09-02