Breaking
Cyber CrimeDeveloping Story

Freelancer phishing campaign nets 80,000 infections

US indicts Russian national accused of using phishing emails to spread TVRAT and DarkVNC malware to freelancers.

··2 hours ago·2 min read
A person wearing fingerless gloves typing on a laptop on a dark surface
Photo by Towfiqu barbhuiya on Unsplash

A federal grand jury in California has indicted a Russian national accused of running a phishing campaign that compromised tens of thousands of freelancers over more than a year. The case, unsealed this week, centers on malware that gave the attackers remote control of victims' computers.

Charges and extradition

Searzhudin Tamirlanovich Aktulaev, 40, was arrested at Larnaca Airport in Cyprus in May 2025 and has been extradited to the United States. He now faces federal charges in the Northern District of California, according to court documents filed in June 2021 and unsealed this week.

Fake accounts, malicious macros

Between June 2016 and November 2017, Aktulaev allegedly created 255 fake user accounts on an unnamed freelance employment platform. Using those accounts, he sent Microsoft Excel attachments with malicious macros to about 80,000 freelancers.

The attachments were designed to download malware onto the targets' systems. The campaign exploited the platform's online messaging system to deliver the malicious files.

Two remote access trojans

The infections relied on two known remote access trojans: TVRAT (also called TeamSPy or TVSPY) and DarkVNC. Both allowed the attackers to take control of infected systems remotely via TeamViewer and VNC Viewer, respectively.

"Both TVRAT and DarkVNC malware sent stolen data from a victim computer to a command-and-control server, from which the stolen data was collected and used by Aktulaev and his co-conspirators to commit fraud or other criminal activity,"

the Department of Justice said. The agency also noted that "[t]he command-and-control domains were paid for using virtual currency, and thousands of computers infected by the TVRAT malware were 'calling back' to a command-and-control domain hosted in the United States."

Stolen credentials and data

The attackers stole e-commerce login credentials and personally identifiable information from victims. Investigators found that half of all infected victims were in the United States, with many located in the Northern District of California.

Next steps in court

Aktulaev is in federal custody and is scheduled to appear before U.S. District Judge Donato on October 5. The indictment is part of a broader push by U.S. authorities to pursue cybercriminals operating overseas.

Parallel action against Sality botnet

On Monday, the U.S. Justice Department announced that it is working to dismantle the malware infrastructure of the Russian-linked Sality botnet in a joint global operation with international law enforcement and private partners.

Why it matters

The scale of this campaign—80,000 targets, 255 fake accounts, and more than a year of suspected activity—highlights how phishing remains a low-cost, high-reach vector for credential theft and remote access. For freelancers and the platforms that serve them, the case suggests that even legitimate communication channels can be weaponized. The Department of Justice's reference to virtual currency payments for command-and-control domains points to a growing challenge for investigators: tracing attacks that rely on anonymous payments. As authorities coordinate internationally—exemplified by the Sality takedown—this case may serve as a reminder that such operations rarely stop at borders.

#malware#phishing#tvrat#darkvnc#cyber crime#freelancers

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories