ZeroHour
Malware

TVRAT

0 mentions in 7 days · 4 in 30 days · 4 total · first seen · last

Timeline

Russian man indicted for spreading malware to 80,000 freelancers

US prosecutors indicted a Russian national for infecting roughly 80,000 freelancers with TVRAT and DarkVNC malware via fake freelance-platform accounts.

Searzhudin Tamirlanovich Aktulaev, 40, was indicted in California for conspiracy, transmission of malicious code, and aggravated identity theft; he was arrested in Cyprus in May 2025 and extradited in August 2026. From June 2016 to November 2017, about 255 fake accounts on a Northern California freelance platform messaged roughly 80,000 users with malicious Excel attachments that ran macros to download malware. The campaign deployed TVRAT (also known as TeamSpy), which exploited a TeamViewer flaw, and DarkVNC via VNC Viewer, exfiltrating stolen data to US-hosted command-and-control servers. About half the victims were in the US, and stolen credentials were used for fraud.

Help Net Security · 12d agoPolicy & legal in the wild

Russian national facing 20 years for malware campaign that infected 80,000 freelancers

US prosecutors indicted Russian national Searzhudin Aktulaev for a 2016 TVRAT malware campaign that infected 80,000 freelance platform users, carrying up to 20 years.

Searzhudin Tamirlanovich Aktulaev was arrested in Cyprus in May 2025, extradited to the US, and appeared in a San Francisco federal court on charges including conspiracy, aggravated identity theft, and damaging protected computers. Between June 2016 and November 2017 he spread a TVRAT (TVSPY/TeamSpy) variant via malicious Microsoft Excel attachments sent from 255 fake accounts on a freelance employment platform's messaging system, infecting about 80,000 users. TVRAT exploited a TeamViewer vulnerability and DarkVNC exploited a bug in VNC Viewer to take over devices; he used the access to steal data and commit fraud, maintained C2 domains, and stored stolen e-commerce credentials for hundreds of victims. About half the victims were in the US, mostly California; the charges carry a maximum 20-year sentence and his next hearing is October 5.

The Record · 13d agoPolicy & legal

Russian Man Extradited Over Malware Campaign Targeting Freelancers

A Russian national was extradited to the US for allegedly spreading TVRAT and DarkVNC malware to 80,000 freelance platform users via Excel attachments.

Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025, extradited on August 28, 2026, and indicted on conspiracy, computer damage, unauthorized access and aggravated identity theft charges. Prosecutors say he and co-conspirators used about 255 fake accounts on a freelance employment platform's messaging system to send macro-laden Excel attachments between June 2016 and November 2017, deploying TVRAT (TVSPY/TeamSpy) and DarkVNC remote access trojans. Thousands of victims were identified on a US-hosted C2 domain, with roughly half of the 80,000 affected users in the US; C2 infrastructure was paid for with virtual currency. If convicted he faces up to 20 years for wire fraud conspiracy plus additional terms and fines.

Infosecurity Magazine · 13d agoPolicy & legal in the wild1

Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands

US DoJ charged extradited Russian Searzhudin Aktulaev for a 2016-2017 Excel macro campaign infecting ~80,000 freelance platform users with TVRAT and DarkVNC.

Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025 and extradited to the US on August 28, facing charges including wire fraud conspiracy and aggravated identity theft. The indictment alleges ~255 fake freelance-platform accounts were used to send Excel macro attachments to about 80,000 users in 2016-2017, deploying TVRAT (TeamSpy/TVSPY) and DarkVNC RATs for remote access and data theft. Thousands of infected machines called back to a US-hosted C2 domain, with stolen credentials and PII stored in the shared email account used in the scheme.

The Hacker News · 13d agoPolicy & legal