A California federal grand jury has indicted Russian national Searzhudin Tamirlanovich Aktulaev over a phishing campaign that targeted 80,000 freelancers with TVRAT and DarkVNC malware.
According to court documents filed in June 2021 and unsealed this week, Aktulaev allegedly used 255 fake user accounts between June 2016 and November 2017. The accounts sent Microsoft Excel attachments containing malicious macros through the online messaging platform of an unnamed freelance employment technology company in California's Northern District.
The macros downloaded malware from the Internet onto victims' systems. TVRAT, also known as TeamSPy and TVSPY, and DarkVNC gave Aktulaev remote control through TeamViewer and VNC Viewer remote administration tools, respectively.
The U.S. Department of Justice said both malware strains sent stolen data to command-and-control servers. The data was then collected and used by Aktulaev and his co-conspirators to commit fraud or other criminal activity. The malware also enabled the theft of e-commerce login credentials and personally identifiable information.
Investigators found that half of the infected victims were in the United States, many in the Northern District of California. Aktulaev was arrested at Larnaca Airport in Cyprus in May 2025, extradited to the United States, and remains in federal custody. He is scheduled to appear before U.S. District Judge Donato on October 5.
Comments
0No comments yet. Be the first to comment.