ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

Russian man indicted for spreading malware to 80,000 freelancers

mediumPolicy & legal exploited in the wildimportance 50
AI summary · glm-5.3-flash

US prosecutors indicted a Russian national for infecting roughly 80,000 freelancers with TVRAT and DarkVNC malware via fake freelance-platform accounts.

Searzhudin Tamirlanovich Aktulaev, 40, was indicted in California for conspiracy, transmission of malicious code, and aggravated identity theft; he was arrested in Cyprus in May 2025 and extradited in August 2026. From June 2016 to November 2017, about 255 fake accounts on a Northern California freelance platform messaged roughly 80,000 users with malicious Excel attachments that ran macros to download malware. The campaign deployed TVRAT (also known as TeamSpy), which exploited a TeamViewer flaw, and DarkVNC via VNC Viewer, exfiltrating stolen data to US-hosted command-and-control servers. About half the victims were in the US, and stolen credentials were used for fraud.

  • Fake client accounts delivered macro-laden Excel attachments that downloaded TVRAT and DarkVNC remote access malware
  • TVRAT exploited a TeamViewer flaw; DarkVNC used VNC Viewer for the same remote-control capability
  • A recovered C2 database listed thousands of victims plus stolen e-commerce credentials for hundreds more
  • Aktulaev remains in federal custody and is scheduled to appear in district court on October 5
Full article304 words · extracted from helpnetsecurity.com · click to collapse

A Russian national accused of using fake accounts on a freelance employment platform to spread malware to approximately 80,000 users has been indicted by a federal grand jury in California.

freelance platform malware

Searzhudin Tamirlanovich Aktulaev, 40, faces charges of conspiracy, transmission of malicious code, and aggravated identity theft, among other counts, the Department of Justice said. He was arrested in Cyprus in May 2025 and extradited to the US in August 2026.

From at least June 2016 through November 2017, Aktulaev and his co-conspirators built around 255 fake accounts on a well-known freelance work platform headquartered in Northern California. They used those accounts to message roughly 80,000 users, posing as prospective clients.

“The messages, which were sent from approximately 255 fake user accounts, contained malicious Microsoft Excel attachments. When opened, the attachments prompted users to run a macro, which then downloaded malware from the Internet ,” US DoJ wrote.

According to the indictment, the campaign deployed two malware families. TVRAT, also known as TVSPY or TeamSpy, exploited a flaw in TeamViewer to hand attackers remote control of infected machines. DarkVNC pulled off the same trick through VNC Viewer.

“Both TVRAT and DarkVNC malware sent stolen data from a victim computer to a command-and-control server,” the DOJ said, adding that Aktulaev and his co-conspirators used that data to commit fraud and other crimes. Domain payments were made in virtual currency, and thousands of compromised machines checked in with infrastructure hosted in the US.

Half the victims were in the US, many in the same Northern California district where the platform is based. Investigators also recovered a database on the command-and-control server listing thousands of victims, along with a shared document holding stolen e-commerce credentials and personal data for hundreds more.

Aktulaev is in federal custody and is scheduled to appear in district court on October 5.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/09/03/russian-national-indicted-freelance-platform-malware/