ZeroHour
The Recordpublished ()ingested

Russian national facing 20 years for malware campaign that infected 80,000 freelancers

mediumPolicy & legalimportance 35
AI summary · glm-5.3-flash

US prosecutors indicted Russian national Searzhudin Aktulaev for a 2016 TVRAT malware campaign that infected 80,000 freelance platform users, carrying up to 20 years.

Searzhudin Tamirlanovich Aktulaev was arrested in Cyprus in May 2025, extradited to the US, and appeared in a San Francisco federal court on charges including conspiracy, aggravated identity theft, and damaging protected computers. Between June 2016 and November 2017 he spread a TVRAT (TVSPY/TeamSpy) variant via malicious Microsoft Excel attachments sent from 255 fake accounts on a freelance employment platform's messaging system, infecting about 80,000 users. TVRAT exploited a TeamViewer vulnerability and DarkVNC exploited a bug in VNC Viewer to take over devices; he used the access to steal data and commit fraud, maintained C2 domains, and stored stolen e-commerce credentials for hundreds of victims. About half the victims were in the US, mostly California; the charges carry a maximum 20-year sentence and his next hearing is October 5.

  • TVRAT variant abused a TeamViewer flaw; DarkVNC exploited a bug in VNC Viewer for device takeover
  • Malicious Excel attachments were distributed via 255 fake accounts on a freelance platform's messaging system
  • Charges include conspiracy, aggravated identity theft, and damaging protected computers; up to 20 years
Full article324 words · extracted from therecord.media · click to collapse

A Russian national was indicted on multiple charges related to a malware campaign he ran in 2016 that infected the devices of more than 80,000 people.

Searzhudin Tamirlanovich Aktulaev appeared in a San Francisco federal court on Monday after being arrested in Cyprus in May 2025 and extradited to the U.S. last week. 

The indictment dates back to 2021, when prosecutors said Aktulaev used a variant of the “TVRAT” malware — also known as “TVSPY” or “TeamSpy.” Between June 2016 and November 2017, Aktulaev used the online messaging platform of a freelance employment tech company and spread the malware to about 80,000 of the site’s users. 

Aktulaev is facing charges of conspiracy, aggravated identity theft and transmission of a program, information, code, and command to cause damage to a protected computer, and more. The charges carry a maximum sentence of 20 years in prison if convicted. 

During his first court appearance in court this week, prosecutors said the messages Aktulaev sent came from 255 fake user accounts and contained malicious Microsoft Excel attachments.

When the attachments were opened, the documents prompted users to take actions that downloaded the malware. 

The indictment is still sealed as of Wednesday and the Justice Department did not say what freelance company was targeted. 

TVRAT allows its users to exploit a vulnerability in remote access tool TeamViewer and take over a victim’s device. Aktulaev also used another strain of malware known as DarkVNC that did the same thing except exploited a bug in another remote administration tool called VNC Viewer. 

Aktulaev used the access to steal data from victims and commit fraud. After infecting devices, he continued to access them through command-and-control domains. About half of all the victims were based in the U.S. mostly in California. 

Aktulaev kept a document with stolen e-commerce login credentials and personal information on hundreds of victims. 

Aktulaev is currently being held in federal custody and his next hearing is on October 5.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/russian-national-facing-20-years-malware-campaign