A Russian national has been extradited to the United States to face charges over an alleged malware operation that targeted approximately 80,000 freelancers through an online employment platform.

 

 

Searzhudin Tamirlanovich Aktulaev, 40, was arrested at Larnaca Airport in Cyprus in May 2025 and extradited to the US on August 28th, 2026. He has since appeared in federal court in San Francisco and remains in federal custody. The indictment against him was originally filed in June 2021 but was only unsealed this week.

US prosecutors allege that Aktulaev and his co-conspirators abused the messaging system of a well-known freelance employment technology company located in California. Authorities have not publicly identified the platform.

The campaign allegedly operated between June 2016 and November 2017. During that period, approximately 255 fake accounts were used to contact freelancers and distribute malicious Microsoft Excel files.

When recipients opened the attachments, they were prompted to enable a macro. Doing so caused malware to be downloaded from the internet and installed on their computers.

Two malware families were allegedly deployed during the operation. One was TVRAT, a remote access trojan also known as TeamSpy and TVSPY. Prosecutors say it provided remote access to compromised computers through TeamViewer. The attackers also used DarkVNC, which provided similar remote-control capabilities through VNC Viewer.

Both threats were capable of sending information taken from infected computers to command-and-control infrastructure controlled by the attackers. Prosecutors allege that Aktulaev and his associates subsequently used stolen information to conduct fraud and other criminal activity.

Investigators discovered thousands of compromised computers communicating with command-and-control infrastructure hosted in the United States. Domains supporting the operation were allegedly purchased using virtual currency.

Approximately half of the victims were located in the United States, with many residing in California’s Northern District. Investigators also discovered a database containing information associated with thousands of victims.

The alleged operation went beyond simply gaining remote access to computers. Authorities say an email account connected to the criminal activity contained a shared document holding e-commerce login credentials and personally identifiable information belonging to hundreds of people.

Aktulaev now faces several federal charges, including conspiracy, computer-related offenses and aggravated identity theft. Some individual charges carry potential prison sentences ranging from five to 20 years, while aggravated identity theft carries a mandatory consecutive two-year sentence for each violation. Any sentence would ultimately be determined by the court if he is convicted.

The FBI investigated the case, while the Justice Department’s Office of International Affairs handled Aktulaev’s extradition.

Aktulaev is scheduled to return to federal court on October 5th for a status conference. The charges contained in the indictment remain allegations, and he is presumed innocent unless proven guilty.

Leave a Reply