Breaking
Cyber CrimeDeveloping Story

Malware Suspect Extradited Over Freelancer Scam

Russian man faces US charges for malware campaign that hit 80,000 freelance platform users.

··2 hours ago·5 min read
icon
Photo by GuerrillaBuzz on Unsplash

The case against Searzhudin Tamirlanovich Aktulaev reads like a slow-burning investigation finally reaching its endgame. US prosecutors say the 40-year-old Russian national helped run a malware operation that touched tens of thousands of freelance workers, and now he is in federal custody in San Francisco to answer for it. His extradition from Cyprus marks the culmination of a years-long effort that spanned multiple countries and involved a sprawling network of fake accounts, remote access trojans, and command infrastructure that stretched across the globe.

The charges are wide-ranging: conspiracy, computer damage, unauthorized access, and aggravated identity theft. But the core allegation is straightforward — that Aktulaev and his alleged co-conspirators weaponized a legitimate freelance employment platform to distribute malware to unsuspecting users, turning a space meant for honest work into a vector for cybercrime.

From Freelance Chat to Malware Delivery

According to the indictment, the operation ran from at least June 2016 through November 2017. During that window, prosecutors allege, Aktulaev and others created approximately 255 fake accounts on the messaging platform of a well-known freelance employment company based in the Northern District of California. Those accounts were used to send malicious Microsoft Excel attachments to targets.

The attack chain relied on social engineering. When a recipient opened an attachment, they were prompted to enable a macro. Doing so triggered the download of malware from the internet, giving the attackers a foothold on the victim's machine. It was a classic lure — a seemingly innocuous spreadsheet that quietly installed something far more sinister.

Two Malware Families, One Goal

The campaign deployed two distinct malware families, both designed to give attackers remote control over infected systems. The first was a variant of TVRAT, also known as TeamViewer Remote Access Trojan or by the aliases TVSPY and TeamSpy. This strain exploited a vulnerability in TeamViewer to seize control of a victim's computer. The second, DarkVNC, achieved similar ends through VNC Viewer, a different remote-access tool.

Both trojans had a common purpose: they siphoned stolen data back to command-and-control (C2) servers. Prosecutors allege that data was collected and used for fraud and other criminal activity. The two-pronged approach meant that even if one remote-access vector was blocked, the attackers had a fallback. It also gave them redundancy in managing their growing network of compromised machines.

A database found on the C2 domain revealed thousands of victims.

That line from the indictment hints at the scale of what investigators uncovered. A shared document on an email account linked to the alleged activity contained e-commerce login credentials and personally identifiable information (PII) for hundreds more victims, suggesting the stolen data was being aggregated and potentially sold or used for further attacks.

The Command Infrastructure Trail

The C2 setup was elaborate. According to the indictment, the domains used for command-and-control were paid for with virtual currency, a move that made financial tracking more difficult for investigators. Despite that, the operation left digital breadcrumbs. Thousands of computers infected with TVRAT were calling back to a C2 domain hosted in the US, which gave law enforcement a critical hook for the investigation.

The scale of the victim pool is striking. Approximately 80,000 users of the freelance platform were affected by the malware distribution campaign. The FBI led the investigation, with the DoJ's Office of International Affairs handling the extradition logistics. The case is being prosecuted in the Northern District of California, where the freelance company is headquartered.

A Global Arrest and Extradition

Aktulaev's path to a US courtroom was not direct. He was arrested in Cyprus in May 2025, more than eight years after the alleged campaign began. The extradition was completed on August 28, 2026, and he made his initial federal court appearance in San Francisco on August 31. He was remanded to federal custody, where he will remain while the case proceeds.

The timing of the arrest — years after the alleged crimes — underscores the slow, methodical nature of international cybercrime investigations. Building a case that crosses borders requires coordination between law enforcement agencies, and extradition treaties can take time to navigate. The DoJ's international affairs office played a key role in securing Aktulaev's transfer to US soil.

Victims Concentrated in the US

The impact of the campaign was not evenly distributed. Approximately half of the victims were in the US, with many of them located in the Northern District of California — the same region where the freelance company is based and where the case is being prosecuted. This geographic concentration likely helped investigators build their case, as it gave them a clear jurisdictional anchor.

  • Approximately 80,000 users of the freelance platform were affected
  • Roughly 255 fake accounts were used on the messaging platform
  • Attack ran from at least June 2016 to November 2017
  • Approximately half of the victims were in the US

The data trail found on the C2 domain revealed thousands of victims, and a shared document on an email account contained e-commerce login credentials and PII for hundreds more. This suggests the attackers were not just compromising machines — they were actively harvesting sensitive information that could be monetized or used for identity theft.

What the Charges Carry

If convicted, Aktulaev faces a maximum of 20 years in prison for conspiracy to commit wire fraud, 10 years for transmitting code to damage protected computers, and two years consecutive for each aggravated identity theft count. Fines could reach $250,000 or twice the gross gain from the criminal activity. The stacking of charges reflects the seriousness of the alleged offenses and the breadth of the criminal enterprise.

For now, Aktulaev remains in federal custody. He is scheduled to appear for a status conference on October 5, where the court will assess the next steps in the case. A conviction is far from certain — the indictment is merely an allegation, and Aktulaev is presumed innocent until proven guilty beyond a reasonable doubt in a court of law.

Why This Matters for Freelancers and Remote Workers

This case is a reminder that the platforms millions of people use to find work can be turned into attack vectors. The attackers exploited the trust inherent in freelance marketplaces — the assumption that a message from a potential client or collaborator is legitimate. That trust is what made the malware distribution so effective.

The use of fake accounts to deliver malicious attachments is a technique that likely continues to evolve. Remote work has expanded the attack surface, and platforms that connect workers with clients are prime targets for social engineering. The lesson for freelancers is to treat unsolicited attachments with caution, especially those that prompt macro execution. For platforms, the case suggests that account verification and monitoring for suspicious activity are not just nice-to-haves but critical security measures. The alleged scale of this operation — 80,000 users affected — shows how damaging a single well-coordinated campaign can be, and how long the consequences can linger before justice catches up.

#malware#extradition#freelance platform#tvrat#darkvnc#department of justice

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories